ZeroHour

CVE-2026-77908

mass

Code injection in Microsoft Dynamics 365 allows network code execution

CVSS 3.1
8.8 high
EPSS
<1%p51
Published
()
Modified
AI analysis

CVE-2026-77908 is a code injection flaw (CWE-94, 'improper control of generation of code') in Microsoft Dynamics 365, meaning attacker-influenced input is turned into executable code without adequate controls. It is triggered over the network by an authenticated attacker: the CVSS vector (PR:L, UI:N) shows the attacker needs valid low-privileged access to the application, but no user interaction or special conditions are required. Successful exploitation yields remote code execution in the context of the affected service, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 8.8, High). Organizations running or using Microsoft Dynamics 365 are potentially affected; the source data does not specify which Dynamics components or versions are impacted, so defenders should confirm scope in Microsoft's advisory. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS places the 30-day exploitation probability at 0.7% (about the 51st percentile).

What to do: Track and apply Microsoft's fix for CVE-2026-77908 as soon as published: check the Microsoft Security Response Center advisory, Windows Update, and the Power Platform/Dynamics 365 admin center, since Dynamics 365 online components are patched service-side by Microsoft. Review and restrict which accounts hold Dynamics 365 permissions, as exploitation requires valid low-privileged credentials, and monitor for anomalous process or script execution associated with Dynamics. Because affected versions and components are not listed in the available data, verify applicability against Microsoft's advisory before triaging.

Affected
Microsoft Dynamics 365
Estimated exposure
mass≈1,000,000+ users across tens of thousands of organizational tenants (platform-scale estimate) — Based on Dynamics 365's deployment scale as a top-tier enterprise CRM/ERP cloud, publicly cited with tens of thousands of organizational customers and millions of seats; Microsoft does not publish install counts and the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.