dynamics_365_on-premises_version_9.1 vulnerabilities
CVEs whose affected-version data names the dynamics_365_on-premises_version_9.1 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-65772High· 8.8Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-65815High· 8.8Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-66301Medium· 6.5Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
CVE-2026-40371High· 8.8Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.