Dynamics 365 Microsoft Dynamics 365

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Dynamics 365.

Recent Microsoft Dynamics 365 Security Advisories

Advisory Title Published
CVE-2025-62211 CVE-2025-62211 Dynamics 365 Field Service (online) Spoofing Vulnerability November 11, 2025
CVE-2025-62210 CVE-2025-62210 Dynamics 365 Field Service (online) Spoofing Vulnerability November 11, 2025
CVE-2025-62206 CVE-2025-62206 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability November 11, 2025
CVE-2025-55238 CVE-2025-55238 Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability September 5, 2025
CVE-2025-53728 CVE-2025-53728 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability August 12, 2025
CVE-2025-49745 CVE-2025-49745 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability August 12, 2025
CVE-2025-21177 CVE-2025-21177 Microsoft Dynamics 365 Sales Elevation of Privilege Vulnerability February 6, 2025
CVE-2024-49053 CVE-2024-49053 Microsoft Dynamics 365 Sales Spoofing Vulnerability November 27, 2024
CVE-2024-43460 CVE-2024-43460 Dynamics 365 Business Central Elevation of Privilege Vulnerability September 17, 2024
CVE-2024-43476 CVE-2024-43476 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability September 10, 2024

By the Year

In 2026 there have been 0 vulnerabilities in Microsoft Dynamics 365. Last year, in 2025 Dynamics 365 had 6 security vulnerabilities published. Right now, Dynamics 365 is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 6 7.22
2024 14 7.21
2023 30 6.36
2022 5 7.80
2021 8 6.64
2020 24 6.32
2019 3 0.00
2018 5 6.08

It may take a day or so for new Dynamics 365 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Dynamics 365 Security Vulnerabilities

Nov 2025: Dynamics 365 Field Service (online) Spoofing Vulnerability
CVE-2025-62211 8.7 - High - November 11, 2025

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

XSS

Nov 2025: Dynamics 365 Field Service (online) Spoofing Vulnerability
CVE-2025-62210 8.7 - High - November 11, 2025

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.

XSS

Nov 2025: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2025-62206 6.5 - Medium - November 11, 2025

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

Information Disclosure

Aug 2025: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2025-53728 6.5 - Medium - August 12, 2025

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

Information Disclosure

Aug 2025: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2025-49745 5.4 - Medium - August 12, 2025

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.

XSS

Jun 2025: Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-49715 7.5 - High - June 20, 2025

Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.

Privacy violation

MS Dynamics 365 (On-Prem) XSS Vulnerability
CVE-2024-43476 5.4 - Medium - September 10, 2024

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 OnPrem XSS Vulnerability
CVE-2024-38211 8.2 - High - August 13, 2024

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 XSS Spoof via Unsanitized Input
CVE-2024-38166 6.1 - Medium - August 06, 2024

An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.

XSS

Jul 2024: Microsoft Dynamics 365 Elevation of Privilege Vulnerability
CVE-2024-38182 9 - Critical - July 31, 2024

Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.

1390

Jul 2024: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-30061 7.3 - High - July 09, 2024

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

AuthZ

Jun 2024: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-35263 5.7 - Medium - June 11, 2024

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Information Disclosure

Microsoft Dynamics 365 On-Prem Cross-Site Scripting (XSS) Vulnerability
CVE-2024-21419 5.4 - Medium - March 12, 2024

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

CVE-2024-21389: Dynamics 365 On-Prem XSS Vulnerability
CVE-2024-21389 7.6 - High - February 13, 2024

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

MS Dynamics 365 On-Prem XSS in Web Forms
CVE-2024-21393 7.6 - High - February 13, 2024

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 Field Service Spoofing Vulnerability
CVE-2024-21394 7.6 - High - February 13, 2024

Dynamics 365 Field Service Spoofing Vulnerability

Microsoft Dynamics 365 On-Prem XSS Vulnerability
CVE-2024-21395 8.2 - High - February 13, 2024

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

MS Dynamics 365 Sales Spoofing CVE-2024-21396
CVE-2024-21396 7.6 - High - February 13, 2024

Dynamics 365 Sales Spoofing Vulnerability

Dynamics 365 CE CrossScripting (XSS) in Customer Engagement
CVE-2024-21327 7.6 - High - February 13, 2024

Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

DYN365 Sales Spoofing Vulnerability
CVE-2024-21328 7.6 - High - February 13, 2024

Dynamics 365 Sales Spoofing Vulnerability

Microsoft Dynamics 365 On-Prem XSS Vulnerability
CVE-2023-36020 5.4 - Medium - December 12, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 Finance & Ops DoS vuln
CVE-2023-35621 7.5 - High - December 12, 2023

Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability

Nov 2023: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36016 6.2 - Medium - November 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Nov 2023: Microsoft Dynamics 365 Sales Spoofing Vulnerability
CVE-2023-36030 6.1 - Medium - November 14, 2023

Microsoft Dynamics 365 Sales Spoofing Vulnerability

XSS

Nov 2023: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36031 7.6 - High - November 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Nov 2023: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36410 7.6 - High - November 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 On-Prem XSS Vulnerability (CVE-2023-36416)
CVE-2023-36416 6.1 - Medium - October 10, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 On-P Info Disclosure CVE-2023-36429
CVE-2023-36429 6.5 - Medium - October 10, 2023

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Exposure of Resource to Wrong Sphere

Microsoft Dynamics 365 (On-Prem) Info Disclosure CVE-2023-36433
CVE-2023-36433 6.5 - Medium - October 10, 2023

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Sep 2023: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36886 7.6 - High - September 12, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Sep 2023: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-38164 7.6 - High - September 12, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Sep 2023: Dynamics Finance and Operations Cross-site Scripting Vulnerability
CVE-2023-36800 7.6 - High - September 12, 2023

Dynamics Finance and Operations Cross-site Scripting Vulnerability

XSS

MS Dynamics 365 On-Prem RCE Vulnerability
CVE-2023-35389 6.5 - Medium - August 08, 2023

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Dynamics 365 Finance Spoofing Vulnerability
CVE-2023-24896 5.4 - Medium - July 14, 2023

Dynamics 365 Finance Spoofing Vulnerability

Microsoft Dynamics 365 (On-Prem) XSS Vulnerability (CVE-2023-33171)
CVE-2023-33171 6.1 - Medium - July 11, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

MS Dynamics 365 On-Prem XSS Vulnerability
CVE-2023-35335 8.2 - High - July 11, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

CVE-2023-28309: Microsoft Dynamics 365 On-Prem XSS Vulnerability
CVE-2023-28309 5.4 - Medium - April 11, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

MS Dynamics 365 On-Prem XSS Vulnerability
CVE-2023-28314 6.1 - Medium - April 11, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

XSS in Microsoft Dynamics 365 On-Prem (CVE-2023-24919)
CVE-2023-24919 5.4 - Medium - March 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 On-Premises XSS Vulnerability
CVE-2023-24920 5.4 - Medium - March 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 XSS Vulnerability (on-premises)
CVE-2023-24921 5.4 - Medium - March 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

CVE-2023-24891: Microsoft Dynamics 365 On-Prem XSS Vulnerability
CVE-2023-24891 5.4 - Medium - March 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 On-Prem: Information Disclosure Vulnerability
CVE-2023-24922 6.5 - Medium - March 14, 2023

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Microsoft Dynamics 365 On-Premises XSS Vulnerability (CVE-2023-24879)
CVE-2023-24879 5.4 - Medium - March 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics Unified Service Desk RCE Vulnerability
CVE-2023-21778 8 - High - February 14, 2023

Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability

Microsoft Dynamics 365 OOB XSS Vulnerability (CVE-2023-21807)
CVE-2023-21807 6.5 - Medium - February 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Microsoft Dynamics 365 (on-prem) XSS Vulnerability in Web Component
CVE-2023-21570 5.4 - Medium - February 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

CVE-2023-21571: D365 on-prem XSS
CVE-2023-21571 5.4 - Medium - February 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

MS Dynamics 365 On-Prem XSS Vulnerability
CVE-2023-21572 6.5 - Medium - February 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Dynamics 365 On-Prem XSS Vulnerability (CVE-2023-21573)
CVE-2023-21573 5.4 - Medium - February 14, 2023

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Dynamics 365 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe