CVE-2026-77908
massCode injection in Microsoft Dynamics 365 allows network code execution
CVE-2026-77908 is a code injection flaw (CWE-94, 'improper control of generation of code') in Microsoft Dynamics 365, meaning attacker-influenced input is turned into executable code without adequate controls. It is triggered over the network by an authenticated attacker: the CVSS vector (PR:L, UI:N) shows the attacker needs valid low-privileged access to the application, but no user interaction or special conditions are required. Successful exploitation yields remote code execution in the context of the affected service, with high impact on confidentiality, integrity and availability (CVSS 3.1 score 8.8, High). Organizations running or using Microsoft Dynamics 365 are potentially affected; the source data does not specify which Dynamics components or versions are impacted, so defenders should confirm scope in Microsoft's advisory. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS places the 30-day exploitation probability at 0.7% (about the 51st percentile).
What to do: Track and apply Microsoft's fix for CVE-2026-77908 as soon as published: check the Microsoft Security Response Center advisory, Windows Update, and the Power Platform/Dynamics 365 admin center, since Dynamics 365 online components are patched service-side by Microsoft. Review and restrict which accounts hold Dynamics 365 permissions, as exploitation requires valid low-privileged credentials, and monitor for anomalous process or script execution associated with Dynamics. Because affected versions and components are not listed in the available data, verify applicability against Microsoft's advisory before triaging.
| Microsoft Dynamics 365 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.