As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0348 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Dynamics
Microsoft released patches for two vulnerabilities in Dynamics 365 and Power Automate on September 8, 2026. CVE-2026-65772 in Dynamics 365 (CVSS 8.8) allows remote code execution, while CVE-2026-77897 in Power Automate (CVSS 7.0) enables privilege escalation. Both online and on-premise deployments are affected.
Why it matters: Organizations running Microsoft Dynamics 365 or Power Automate must apply these patches immediately to prevent remote code execution and unauthorized privilege escalation in both cloud and on-premises environments.
- Source published
- First seen by Cybersecurity Tracker