ZeroHour

CVE-2026-65772

mass

Deserialization RCE in Microsoft Dynamics 365

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-65772 is a deserialization of untrusted data flaw (CWE-502) in Microsoft Dynamics 365 that allows an authorized (authenticated, low-privilege) attacker to execute code over the network. It is triggered when the application processes attacker-controlled serialized data, and the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms network exploitation with low attack complexity, low required privileges, and no user interaction. Successful exploitation yields high impact to confidentiality, integrity, and availability, effectively amounting to remote code execution within the affected Dynamics 365 environment. Any organization running the affected Microsoft Dynamics 365 deployments is in scope, with authenticated users or compromised low-privileged accounts able to trigger the flaw; the available data does not specify which Dynamics 365 editions or version ranges are affected. As of the September 2026 Patch Tuesday coverage, there is no evidence of in-the-wild exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns roughly a 0.9% probability of exploitation within 30 days (58th percentile).

What to do: Apply the Microsoft security update for CVE-2026-65772 released in the September 2026 Patch Tuesday cycle, prioritizing internet-facing, multi-user, or production Dynamics 365 environments where low-privileged users can reach the vulnerable endpoint. Because the affected version range is not specified here, verify applicability against Microsoft's advisory and confirm your deployed editions/versions before and after patching. Until patched, restrict and monitor authenticated access to Dynamics 365, and watch for changes in EPSS, KEV, or public proof-of-concept status.

Affected
Microsoft Dynamics 365
Estimated exposure
masson the order of millions of users across hundreds of thousands of customer organizations (estimate; the subset running vulnerable versions is unknown) — Dynamics 365 is Microsoft's mainstream CRM/ERP suite whose installed base is publicly reported in the hundreds of thousands of organizations and millions of users, so exposure was scaled from that footprint; the number of deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs

Microsoft Patch Tuesday, September 2026 Security Update Review

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, including 113 critical and two actively exploited Windows privilege escalation flaws.

Microsoft's September 2026 Patch Tuesday fixes 974 vulnerabilities, its largest release ever, including 113 critical and 860 important, covering Windows HTTP.sys, Hyper-V, Entra ID, Exchange Server, Office, DNS, and more. Two zero-days are confirmed exploited in the wild: CVE-2026-81963 (Windows Update Stack EoP) and CVE-2026-85880 (ALPC heap overflow), both letting authenticated attackers gain SYSTEM privileges. Notable criticals include an Entra ID authentication bypass (CVE-2026-62916) and multiple Windows DNS Server and Office remote code execution flaws.

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.