CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

NCSC-2026-0348 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Dynamics

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6771

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0348 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Dynamics

Microsoft released patches for two vulnerabilities in Dynamics 365 and Power Automate on September 8, 2026. CVE-2026-65772 in Dynamics 365 (CVSS 8.8) allows remote code execution, while CVE-2026-77897 in Power Automate (CVSS 7.0) enables privilege escalation. Both online and on-premise deployments are affected.

Why it matters: Organizations running Microsoft Dynamics 365 or Power Automate must apply these patches immediately to prevent remote code execution and unauthorized privilege escalation in both cloud and on-premises environments.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary