CVE-2026-32210Disclosure(microsoft / dynamics_365)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch microsoft dynamics_365 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dynamics_365

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 4 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 11 total mentions across 5 days

Affected systems

Vendors
Products
dynamics_365

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 5d
01234Mentions · 2026-04-24: 3Mentions · 2026-04-25: 1Mentions · 2026-04-27: 2Mentions · 2026-04-28: 1Mentions · 2026-05-12: 4Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 2Technical Details · 2026-05-12: 304-2404-2504-2704-2805-12
Signal classification3 categories
Disclosure
654.5%
General
436.4%
Patch
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-243
Disclosure1General2
2026-04-251
Disclosure1
2026-04-272
Disclosure1Patch1
2026-04-281
General1
2026-05-124
Disclosure3General1
Full discourse11 posts
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 4.23 Microsoft Dynamics 365 (online) Spoofing Vulnerability CVE-2026-32210 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32210

    Post summary

    Microsoft announced a patch for a spoofing vulnerability (CVE‑2026‑32210) in Dynamics 365 online, providing a link to the official update guide with mitigation details.

    10100142
    85 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32210 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. https://www.cve.org/CVERecord?id=CVE-2026-32210

    Post summary

    A new SSRF vulnerability (CVE-2026-32210) has been disclosed for Microsoft Dynamics 365 (Online), with technical details provided but no information on patches, exploits, or active exploitation.

    00020154
    57.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-32210 CVSS: 9.3 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory CRITICAL: CVE-2026-32210 (CVSS 9.3) — microsoft dynamics 365

    Post summary

    The post announces a critical Microsoft Dynamics 365 vulnerability (CVE-2026‑32210) with a CVSS score of 9.3, but provides no PoC, exploit, or patch information.

    1000068
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-32210 (CVSS 9.3) — microsoft dynamics 365 Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

    Post summary

    A critical SSRF vulnerability (CVE‑2026‑32210) in Microsoft Dynamics 365 has been disclosed, rated CVSS 9.3, allowing attackers to spoof internal network traffic.

    1000046
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVSS 9.3 CRITICAL · CVE-2026-32210 · 9.3 → 3.1 CRITICAL: CVE-2026-32210 (CVSS 9.3) — microsoft dynamics 365

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑32210) in Microsoft Dynamics 365 with a CVSS score of 9.3, but provides no additional technical or mitigation information.

    1000040
    210 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-20133 2 - CVE-2025-20333 3 - CVE-2026-32201 4 - CVE-2026-32210 5 - CVE-2026-25253 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without providing further technical or operational details.

    00010684
    1.7K followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-32210 「脆弱性を解決するために、お客様が取るべきアクションはありません」 影響: なりすまし 最大深刻度: 緊急 CVSS:3.1 9.3 / 8.1 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2048674394499850318

    Post summary

    Microsoft’s security update announces CVE-2026-32210 (impersonation) with high severity, but indicates no customer action is needed and that no exploitation is known.

    1000087
    85 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-32210-microsoft-dynamics-365 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text consists solely of a link and hashtags, offering no concrete information about the CVE beyond its mention.

    0000026
    210 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-32210 | Microsoft Dynamics 365 (online) Spoofing Vulnerability https://www.aakashrahsi.online/post/cve-2026-32210 https://t.co/k8FRZ7C7L7

    Post summary

    The post merely advertises CVE‑2026‑32210 as a spoofing issue in Microsoft Dynamics 365 online, linking to an external article but offering no further technical or mitigation details.

    0000028
    1 followersView on X
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-32210 (Dynamics 365) is a critical SSRF. High severity, yet constrained by authentication, cloud controls, and currently no in-wild exploitation. See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-04-23/TIER_2_CVE-2026-32210.md #CyberSecurity #VulnerabilityManagement #DigitalIdentity #DPI #CVE

    Post summary

    CVE-2026-32210 is a critical Server‑Side Request Forgery in Dynamics 365; it's high severity but constrained by authentication and cloud controls with no reported in‑wild exploitation.

    0000065
    45 followersView on X
  • WindowsForum@windowsforum
    General

    🪟 CVE-2026-32210: Dynamics 365 “spoofing risk” means attackers don’t need to break Windows—they just need people to believe stuff. Still, security teams have to clean the trust mess. https://windowsforum.com/threads/cve-2026-32210-spoofing-risk-in-dynamics-365-online-what-security-teams-should-do.414935/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #Dynamics365 #CloudSecurity #SpoofingRisk #Cve202632210 https://t.co/LO1GLBTm64

    Post summary

    The tweet announces CVE‑2026‑32210 in Dynamics 365 as a spoofing risk but provides no PoC, exploit code, active exploitation evidence, patch, technical details, or debunking claim.

    0000058
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdynamics_365---

Explore more