CVE-2026-65815: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability? An attacker could exploit the vulnerability by sending specially crafted data that is processed by the vulnerable component, causing it to deserialize untrusted input and execute unintended actions within the service context.

Affected Products (1)

Microsoft Dynamics

  • Microsoft Dynamics 365 (on-premises) version 9.1

Security Updates (1)

Acknowledgments

f7d8c52bec79e42795cf15888b85cbad

Revision History

  • 2026-08-11: Information published.