Server-Side Request Forgery Vulnerability in Microsoft Dynamics 365 by Microsoft
CVE-2026-32210

9.3CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
23 April 2026

What is CVE-2026-32210?

A vulnerability exists in Microsoft Dynamics 365 (Online) that allows an unauthorized attacker to exploit server-side request forgery (SSRF) techniques for performing spoofing attacks over a network. This could result in unauthorized access to sensitive network resources. Ensure your system is updated to the latest version to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Microsoft Dynamics 365 (online) -

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.