ThreatCluster

Critical Remote Code Execution Vulnerabilities in Microsoft Dynamics 365 On-Premises

First seen 9 Sep 2026, 09:12 UTC Cybersecurity-Help.Cz 71

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities (SB2026090874 and SB2026090875) have been identified in Microsoft Dynamics 365 On-Premises, allowing remote attackers to execute arbitrary code on affected systems. Both vulnerabilities stem from improper input validation when processing serialized data, enabling attackers to compromise systems completely. The vulnerabilities affect all versions of Microsoft Dynamics 365 On-Premises. Successful exploitation could lead to severe security breaches. Users are advised to install updates from the vendor's website to mitigate these risks. No specific CVEs were mentioned in the articles. The vulnerabilities were reported on the same day, indicating a potentially coordinated disclosure. Organizations using Microsoft Dynamics 365 On-Premises should prioritize patching to prevent exploitation.

Key Points: • Two critical vulnerabilities in Microsoft Dynamics 365 On-Premises allow remote code execution. • Both vulnerabilities result from improper input validation of serialized data. • Immediate patching is recommended to prevent complete system compromise.

Ask AI about this cluster

Timeline

2026-09-09
Vulnerabilities SB2026090874 and SB2026090875 disclosed
Two remote code execution vulnerabilities were reported in Microsoft Dynamics 365 On-Premises, affecting all versions.
Cybersecurity-Help.Cz
2026-09-09
Vendor updates recommended
Users are urged to install updates from the vendor's website to mitigate the vulnerabilities.
Cybersecurity-Help.Cz