Description
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Microsoft Dynamics 365 Customer Engagement allows an attacker who already has authorized access to the application to inject and execute arbitrary code. This is a code injection flaw (CWE-94) that can be leveraged over a network connection, enabling the attacker to run malicious payloads with the privileges of the authenticated user and potentially access, modify, or delete data within the system.

Affected Systems

Microsoft Dynamics 365 Customer Engagement V9.1. No specific sub‑versions are listed, so any instance of this product that has not yet applied the vendor’s security update is potentially affected.

Risk and Exploitability

The CVSS score of 8.8 denotes high severity, and the absence of an EPSS score indicates that current evidence of exploitation is unknown, yet the flaw remains in the CISA KEV catalog as not listed. The likely attack vector is a network‑based attack requiring authorized credentials; consequently, the risk is substantial for organizations that have exposed Dynamics 365 to internal or external networks without additional controls.

Generated by OpenCVE AI on September 9, 2026 at 21:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Security Update for CVE‑2026‑77908 as released by Microsoft
  • Restrict network access to the Dynamics 365 instance to trusted IP ranges or VPN tunnels to limit potential attackers
  • Enforce least‑privilege authentication and regularly review user accounts that have access to code‑generation or upload functions

Generated by OpenCVE AI on September 9, 2026 at 21:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Title Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft dynamics 365
Weaknesses CWE-94
CPEs cpe:2.3:a:microsoft:dynamics_365:*:*:*:*:customer_engagement:*:*:*
Vendors & Products Microsoft
Microsoft dynamics 365
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Dynamics 365
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:31.667Z

Reserved: 2026-08-21T17:26:55.613Z

Link: CVE-2026-77908

cve-icon Vulnrichment

Updated: 2026-09-09T18:11:45.450Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:20:41.000

Modified: 2026-09-09T19:17:47.147

Link: CVE-2026-77908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T01:15:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')