Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-77908

Опубликовано: 08 сент. 2026
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability?

An authenticated attacker with low-level access to an affected server could send a specially crafted request to execute code on the server. User interaction is not required.

Обновления

ПродуктСтатьяОбновление
Microsoft Dynamics 365 Customer Engagement V9.1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

N/A

EPSS

Процентиль: 51%
0.00689
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
11 дней назад

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

CVSS3: 8.8
github
11 дней назад

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

EPSS

Процентиль: 51%
0.00689
Низкий

8.8 High

CVSS3