CVE-2026-47646Disclosure(microsoft / dynamics_365_customer_voice)

LOWCVSS 6.1 · MEDIUM

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch microsoft dynamics_365_customer_voice systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dynamics_365_customer_voice

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
dynamics_365_customer_voice

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-07-09: 5Patch / Workaround · 2026-07-09: 2Technical Details · 2026-07-09: 507-09
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets3 URLs
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-47646 — CVSS 9.3/10 █████████░ Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/DJsBiGkV8A

    Post summary

    Patch and severity details for a critical XSS vulnerability in Dynamics 365 Customer Voice are announced; no exploitation or PoC disclosed.

    10000107
    64 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    Microsoft Dynamics 365 Customer Voice has a CVSS 9.3 XSS vulnerability (CVE-2026-47646) enabling network spoofing. Review instances and apply updates. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/jWepX1rYN4

    Post summary

    CVE‑2026‑47646 is an XSS vulnerability in Microsoft Dynamics 365 Customer Voice with a CVSS score of 9.3, urging users to review instances and install available updates.

    0000052
    91 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 Critical XSS in Dynamics 365 Customer Voice (CVE-2026-47646, CVSS 9.3) Malicious survey links → session hijacking + credential theft. 🔗 https://threataft.com/articles/microsoft-dynamics-365-customer-voice-xss-spoofing-cve-2026-47646?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel

    Post summary

    A critical cross‑site scripting (XSS) vulnerability in Dynamics 365 Customer Voice (CVE‑2026‑47646) has been disclosed, indicating potential for session hijacking and credential theft via malicious survey links, but no evidence of current exploitation, patch, or PoC is provided.

    0000061
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofin… https://www.cve.org/CVERecord?id=CVE-2026-47646 ----- Traducción: CVE-2026-47646 Neu… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑47646, describing an XSS flaw in Dynamics 365 Customer Voice without providing PoC, exploit code, active exploitation evidence, or a patch.

    0000041
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofin… https://www.cve.org/CVERecord?id=CVE-2026-47646

    Post summary

    The text announces CVE-2026-47646, an XSS flaw in Dynamics 365 Customer Voice that allows unsanitized input rendering.

    00000712
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdynamics_365_customer_voice---

Explore more