Microsoft Dynamics 365 Vulnerability Leading to Possible Code Execution
CVE-2026-42898

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-42898?

A vulnerability in Microsoft Dynamics 365 (On-Premises) allows an authorized attacker to exploit improper control over code generation, leading to possible execution of arbitrary code across the network. This flaw highlights the importance of stringent security measures to prevent unauthorized code execution and ensures that proper patching and updates are applied to protect sensitive data and system integrity.

Affected Version(s)

Microsoft Dynamics 365 (on-premises) version 9.1 9.0 < 9.1.44.15

News Articles

It's Patch Tuesday for Microsoft and Not a Zero-Day In Sight

It's the first time in two years with no zero-days. But with 137 flaws to patch, including nine critical ones, admins still have plenty of work to do.

17 hours ago

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Dark Reading

  • Vulnerability published

  • Vulnerability Reserved

.