CVE-2026-65772
- EPSS 0.93%
- Veröffentlicht 08.09.2026 17:17:46
- Zuletzt bearbeitet 07.10.2026 14:32:13
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-77908
- EPSS 0.69%
- Veröffentlicht 08.09.2026 17:13:35
- Zuletzt bearbeitet 29.09.2026 19:40:46
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-66301
- EPSS 0.68%
- Veröffentlicht 11.08.2026 17:05:19
- Zuletzt bearbeitet 17.08.2026 13:21:25
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
CVE-2026-65815
- EPSS 0.91%
- Veröffentlicht 11.08.2026 17:05:05
- Zuletzt bearbeitet 17.08.2026 13:20:21
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-47647
- EPSS 0.78%
- Veröffentlicht 18.06.2026 21:42:40
- Zuletzt bearbeitet 25.06.2026 18:57:14
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-40371
- EPSS 0.63%
- Veröffentlicht 09.06.2026 17:17:05
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
CVE-2026-33821
- EPSS 0.66%
- Veröffentlicht 12.05.2026 16:59:38
- Zuletzt bearbeitet 15.05.2026 18:26:18
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
CVE-2026-42833
- EPSS 0.75%
- Veröffentlicht 12.05.2026 16:59:35
- Zuletzt bearbeitet 01.06.2026 19:16:44
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42898
- EPSS 1.19%
- Veröffentlicht 12.05.2026 16:59:06
- Zuletzt bearbeitet 14.05.2026 14:31:46
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-32210
- EPSS 0.58%
- Veröffentlicht 23.04.2026 21:35:47
- Zuletzt bearbeitet 05.05.2026 14:10:29
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.