CVE-2026-47647Disclosure(microsoft / dynamics_365)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft dynamics_365 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dynamics_365

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-06-19); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dynamics_365

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-06-19: 4Mentions · 2026-06-25: 1Active Exploitation · 2026-06-19: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-19: 3Technical Details · 2026-06-25: 106-1906-25
Signal classification4 categories
Disclosure
240.0%
Active Exploitation
120.0%
General
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-194
Active Exploitation1Disclosure2General1
2026-06-251
Patch1
Full discourse5 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-47647 (CVSS 9.9) - Improper access control in Microsoft Dynamics 365 enables privilege escalation over network. Authorized attackers can exploit remotely. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/CSwPbhcmuI

    Post summary

    The tweet alerts of a high‑severity vulnerability (CVE‑2026‑47647) in Microsoft Dynamics 365 that allows remote privilege escalation, urging immediate patching.

    0000158
    52 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🔴 CVE-2026-47647 in Dynamics 365 is actively exploited, letting attackers escalate privileges to access sensitive data. CVSS 9.8. Patch immediately—this bypasses standard security controls. #NerdieNews #CyberSecurity #Vulnerability https://t.co/YWbBFGbnJj

    Post summary

    CVE‑2026‑47647 is actively exploited in Dynamics 365, enabling privilege escalation with a high CVSS of 9.8, and urgent patching is required.

    0000032
    68 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-47647 Privilege Escalation via Improper Access Control in Microsoft Dynamics 365 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-47647

    Post summary

    A brief CVE reference and headline are provided, but no detailed technical or exploit information is offered.

    0000057
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47647 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-47647 ----- Traducción: CVE-2026-47647 Control de acceso inapropiado en Microsoft Dynamics 36… http://infoflow.cloud`

    Post summary

    The tweet reports CVE‑2026‑47647, describing an improper access control flaw in Microsoft Dynamics 365 that enables privileged escalation over a network, and directs readers to the CVE record for details.

    0000046
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47647 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-47647

    Post summary

    The statement discloses an improper access control flaw in Microsoft Dynamics 365 that permits privilege escalation for authorized attackers, but it contains no proof‑of‑concept, exploit code, patch information, or evidence of active exploitation.

    00000299
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdynamics_365---

Explore more