CVE-2026-42833Disclosure(microsoft / dynamics_365)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft dynamics_365 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-250

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dynamics_365

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
dynamics_365

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-12: 2Mentions · 2026-05-14: 1Mentions · 2026-05-17: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-17: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-17: 105-1205-1405-17
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-122
Disclosure2
2026-05-141
Active Exploitation1
2026-05-171
Patch1
Full discourse4 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    ثغرة (CVE-2026-42898) في (Microsoft Dynamics 365 On-Premises) خطيرة جداً. 🚨 التقييم: (CVSS 9.9) النوع: (Code Injection) النتيجة: تنفيذ كود خبيث على السيرفر عن طريق الشبكة. لكن فيه شرط مهم: المهاجم يحتاج حساب داخل النظام، حتى لو بصلاحيات منخفضة. 📍 قبل الثغرة، وش هو (Dynamics 365)؟ هو نظام تستخدمه الشركات لإدارة العملاء والعمليات الداخلية. غالباً تلقاه مرتبط أشياء حساسة مثل: 🔹 بيانات العملاء والعقود والفواتير. 🔹 عمليات البيع والبيانات المالية. 🔹 ربط مع (Active Directory) أو قواعد بيانات أخرى. عشان كذا، اختراقه ممكن يتسبب بخسائر كبيره. 📍 وين تكمن المشكلة؟ الثغرة تؤثر على (Dynamics 365 On-Premises)، يعني النسخة اللي تكون مركبة على سيرفرات الشركة نفسها، مو النسخة السحابية اللي تديرها مايكروسوفت. في بيئات الـ (On-Premises)، التحديث مسؤولية الشركة. إذا فريق الـ (IT) تأخر، الثغرة تبقى مفتوحة داخل بيئة الشركة. ⚙️ المعلومات المؤكدة للاستغلال: 🔹 (Attack Vector: Network) 🔹 (Attack Complexity: Low) 🔹 (Privileges Required: Low) 🔹 (User Interaction: None) 🔹 (Scope: Changed) التأثير عالي جداً (High) على السرية، السلامة، والتوافر. المهاجم ما يحتاج يقنع المستخدم يضغط رابط، وما يحتاج صلاحيات (Admin).. فقط يحتاج حساب داخل (Dynamics). 📍 وش نوع الخلل برمجياً؟ الثغرة مصنفة (CWE-94: Improper Control of Generation of Code). الاستغلال يدور حول (Saved State of a Process Session) داخل النظام. داخل (Dynamics) فيه عمليات وجلسات عمل تحفظ حالتها (وين توقفت العملية؟ وش الخطوة الحالية؟). المهاجم يعدل بيانات مرتبطة بهذي الحالة، ولما يعالجها النظام بطريقة غير آمنة، السيرفر ينفذ كود ما كان المفروض ينفذه. ⚠️ ليش (Scope: Changed) مخيفة هنا؟ الخطر لانه يسمح بتنفيذ كود على مستوى السيرفر! ولأن أثر الثغرة ما يبقى داخل حدود التطبيق، الضرر يمتد حسب بيئة الشركة. (Dynamics) غالباً مربوط مع: 🔹 (Active Directory) و (SQL Server) 🔹 أنظمة مالية و (ERP) يعني تنفيذ كود على سيرفر (Dynamics) ممكن يكون نقطه دخول الى الشبكة الداخلية. 📍 تنبيه صحيح الثغرة مو (Pre-Auth) وما يقدر أي شخص من الإنترنت يستغلها بدون حساب. لكن هذا مو معناته نهمل تحديثها واغلاقها! حسابات الموظفين تنسرق كل يوم عن طريق (Phishing) أو تكرار الباسووردات. المهاجم يكفيه حساب موظف عادي داخل (Dynamics) كبداية، ويستغل الثغرة 📍 الإصدارات المتأثرة النسخ المتأثرة من (9.1.1.914) إلى أقل من (9.1.45.11). راجع رقم النسخة الفعلي على السيرفر فوراً، ولا تعتمد على اسم المنتج فقط. (للمعلومية: ظهرت ثغرة ثانية في نفس التحديث CVE-2026-42833 بتقييم 9.1 لتنفيذ كود أيضاً.) 💡وش تسوي الآن؟ حدّث (Dynamics 365 On-Premises) إلى (9.1.45.11) طبّق مبدأ (Least Privilege) وراجع الحسابات اللي تقدر تعدل (Workflows) أو (Business Processes). راقب تنفيذ العمليات في أوقات غير معتادة، وراجع أي تغييرات غريبة في (Process Sessions).

    Post summary

    The advisory announces a critical Code Injection vulnerability in Dynamics 365 On‑Premises, provides detailed technical information, and urges users to apply the latest patch (9.1.45.11) and enforce least‑privilege controls.

    06027163.7K
    50.0K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    CVE-2026-42833 in Microsoft Dynamics 365 is under active exploitation — attackers can execute remote code on on-premises systems. Patch now to prevent full compromise. #NerdieNews #CyberSecurity #InfoSec #Ransomware https://t.co/VQ7WeW7Irg

    Post summary

    CVE-2026-42833 in Microsoft Dynamics 365 is being actively exploited for remote code execution on on-premises systems; users are urged to apply the available patch immediately.

    0000041
    63 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42833 Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-42833 ----- Traducción: CVE-2026-42833 Ejecución con privilegios innece… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-42833, describing an unnecessary privileges execution flaw in Microsoft Dynamics 365 that allows authorized code execution over a network.

    0000036
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42833 Execution with unnecessary privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-42833

    Post summary

    The text announces CVE-2026-42833, noting it allows an authorized attacker to execute code over a network due to unnecessary privileges.

    00000250
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdynamics_365---

Explore more