CVE-2026-65815: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Overview
- Severity
- High (CVSS 8.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
Description
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An attacker could exploit the vulnerability by sending specially crafted data that is processed by the vulnerable component, causing it to deserialize untrusted input and execute unintended actions within the service context.
Affected Products (1)
Microsoft Dynamics
- Microsoft Dynamics 365 (on-premises) version 9.1
Security Updates (1)
Acknowledgments
f7d8c52bec79e42795cf15888b85cbad
Revision History
- 2026-08-11: Information published.