External risk intelligence

Microsoft Dynamics 365 (on-premises) could allow an internal attacker to run system commands.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-42833

Microsoft Dynamics 365 (on-premises) contains a flaw that allows an internal attacker to run unauthorized system commands. This risk could enable them to gain full administrative control over the application server and access sensitive enterprise data.

2Halo Surface Signal

Code Injection

Microsoft Dynamics 365

9.1 to before 9.1.45.11

External exposure likelihood

Halo Surface Signal score for CVE-2026-42833

Microsoft Dynamics 365 (on-premises) is an enterprise application typically hosted within internal corporate networks or behind VPNs. The vulnerability requires existing valid user credentials, and the context specifically targets an internal attacker, indicating the attack surface is not designed for direct public internet exposure.

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Microsoft Dynamics 365 (on-premises) allows an authenticated attacker to execute code over a network. This is concerning because it could let someone gain unauthorized control of systems.

  • Affects Dynamics 365 (on-premises).
  • Requires existing valid user credentials.
  • Can lead to unauthorized code execution.

Attack Path

How an attacker could exploit the issue

An attacker with administrator privileges on Microsoft Dynamics 365 (on-premises) can exploit this flaw to gain control of the server. They would send specially crafted network requests to trigger the vulnerability, allowing them to execute arbitrary code with high privileges.

  • Requires administrative access.
  • Network-based attack vector.
  • Targets Dynamics 365 (on-premises).

Live Threat

Current exploitation, exposure, and threat context

This vulnerability allows an authorized attacker to execute code remotely over a network within Microsoft Dynamics 365 (on-premises). While requiring authenticated access, the potential for privilege escalation and significant impact makes it a target for adversaries seeking to move laterally within an organization or compromise sensitive data. The on-premises nature and authentication requirement suggest a more focused threat landscape.

  • Exploitation requires valid credentials.
  • No public exploit is currently observed.
  • Targeting internal or authenticated users.

Priority actions

Operational Fix

Recommended remediation, mitigation, and detection steps

Prioritize immediate patching of Microsoft Dynamics 365 on-premises instances affected by this critical vulnerability, as it allows authenticated attackers to execute code over a network. If patching is delayed, isolate affected systems from the network to prevent lateral movement and unauthorized code execution.

  • Patch Dynamics 365 to version 9.1.45.11.
  • Isolate affected Dynamics 365 instances.
  • Monitor network traffic for exploitation indicators.

Frequently asked questions

What is Microsoft Dynamics 365 (on-premises)?

Microsoft Dynamics 365 (on-premises) is an enterprise resource planning (ERP) and customer relationship management (CRM) software suite. Businesses use it to manage core business processes like sales, customer service, finance, and operations, with the 'on-premises' version being installed and run on a company's own servers.

What is the weakness in CVE-2026-42833?

CVE-2026-42833 is a code injection vulnerability. This means an attacker can trick the software into running unintended code, which could allow them to take control of the system.

How can an attacker exploit this vulnerability?

An attacker needs to be already authenticated with valid user credentials to exploit this vulnerability. They can then send specially crafted network requests to trigger the flaw and execute their own code on the system.

Who should be concerned about this threat?

Organizations running Microsoft Dynamics 365 (on-premises) should be concerned. Since the vulnerability requires authenticated access and is typically found in systems behind a network, it poses a risk to internal operations rather than directly to the public internet.

What should I do if I use this software?

The primary recommended action is to update Microsoft Dynamics 365 to the patched version. If immediate patching isn't possible, isolating the affected systems from the network can help prevent further exploitation.

References