AI analysis
CVE-2026-65772 is a deserialization of untrusted data flaw (CWE-502) in Microsoft Dynamics 365 that allows an authorized (authenticated, low-privilege) attacker to execute code over the network. It is triggered when the application processes attacker-controlled serialized data, and the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms network exploitation with low attack complexity, low required privileges, and no user interaction. Successful exploitation yields high impact to confidentiality, integrity, and availability, effectively amounting to remote code execution within the affected Dynamics 365 environment. Any organization running the affected Microsoft Dynamics 365 deployments is in scope, with authenticated users or compromised low-privileged accounts able to trigger the flaw; the available data does not specify which Dynamics 365 editions or version ranges are affected. As of the September 2026 Patch Tuesday coverage, there is no evidence of in-the-wild exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns roughly a 0.9% probability of exploitation within 30 days (58th percentile).
What to do: Apply the Microsoft security update for CVE-2026-65772 released in the September 2026 Patch Tuesday cycle, prioritizing internet-facing, multi-user, or production Dynamics 365 environments where low-privileged users can reach the vulnerable endpoint. Because the affected version range is not specified here, verify applicability against Microsoft's advisory and confirm your deployed editions/versions before and after patching. Until patched, restrict and monitor authenticated access to Dynamics 365, and watch for changes in EPSS, KEV, or public proof-of-concept status.
Estimated exposure
masson the order of millions of users across hundreds of thousands of customer organizations (estimate; the subset running vulnerable versions is unknown) — Dynamics 365 is Microsoft's mainstream CRM/ERP suite whose installed base is publicly reported in the hundreds of thousands of organizations and millions of users, so exposure was scaled from that footprint; the number of deployments…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.