External risk intelligence

Microsoft Dynamics 365 (on-premises) could allow an internal attacker to run system commands.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-42833

Microsoft Dynamics 365 (on-premises) is an enterprise application typically hosted within internal corporate networks or behind VPNs. The vulnerability requires existing valid user credentials, and the context specifically targets an internal attacker, indicating the attack surface is not designed for direct public internet exposure.

Code Injection

Microsoft Dynamics 365

9.1 to before 9.1.45.11

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability in Microsoft Dynamics 365 (on-premises) allows an authenticated attacker to execute code over a network. This is concerning because it could let someone gain unauthorized control of systems.

  • Affects Dynamics 365 (on-premises).
  • Requires existing valid user credentials.
  • Can lead to unauthorized code execution.

Attack Path

How an attacker could exploit the issue

An attacker with administrator privileges on Microsoft Dynamics 365 (on-premises) can exploit this flaw to gain control of the server. They would send specially crafted network requests to trigger the vulnerability, allowing them to execute arbitrary code with high privileges.

  • Requires administrative access.
  • Network-based attack vector.
  • Targets Dynamics 365 (on-premises).

Live Threat

Current exploitation, exposure, and threat context

This vulnerability allows an authorized attacker to execute code remotely over a network within Microsoft Dynamics 365 (on-premises). While requiring authenticated access, the potential for privilege escalation and significant impact makes it a target for adversaries seeking to move laterally within an organization or compromise sensitive data. The on-premises nature and authentication requirement suggest a more focused threat landscape.

  • Exploitation requires valid credentials.
  • No public exploit is currently observed.
  • Targeting internal or authenticated users.

Operational Fix

Recommended remediation, mitigation, and detection steps

Prioritize immediate patching of Microsoft Dynamics 365 on-premises instances affected by this critical vulnerability, as it allows authenticated attackers to execute code over a network. If patching is delayed, isolate affected systems from the network to prevent lateral movement and unauthorized code execution.

  • Patch Dynamics 365 to version 9.1.45.11.
  • Isolate affected Dynamics 365 instances.
  • Monitor network traffic for exploitation indicators.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Dynamics 365 (on-premises)?

Microsoft Dynamics 365 (on-premises) is an enterprise resource planning (ERP) and customer relationship management (CRM) software suite. Businesses use it to manage core business processes like sales, customer service, finance, and operations, with the 'on-premises' version being installed and run on a company's own servers.

What is the weakness in CVE-2026-42833?

CVE-2026-42833 is a code injection vulnerability. This means an attacker can trick the software into running unintended code, which could allow them to take control of the system.

How can an attacker exploit this vulnerability?

An attacker needs to be already authenticated with valid user credentials to exploit this vulnerability. They can then send specially crafted network requests to trigger the flaw and execute their own code on the system.

Who should be concerned about this threat?

Organizations running Microsoft Dynamics 365 (on-premises) should be concerned. Since the vulnerability requires authenticated access and is typically found in systems behind a network, it poses a risk to internal operations rather than directly to the public internet.

What should I do if I use this software?

The primary recommended action is to update Microsoft Dynamics 365 to the patched version. If immediate patching isn't possible, isolating the affected systems from the network can help prevent further exploitation.

References