CVE-2026-55944: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
CSIRTS triage
- What
- Deserialization of untrusted data in Dynamics NAV allows unauthorized remote code execution.
- Who is affected
- Users of Microsoft Dynamics NAV and Dynamics 365 Business Central are affected.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerability and its high CVSS score.
- Action
- Apply the security update for CVE-2026-55944 as soon as possible.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Dynamics NAV and Dynamics 365 Business Central
Get an email when a new Dynamics NAV and Dynamics 365 Business Central advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55944
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-559441.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55944 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Dynamics NAV: Vulnerability allows code executioncert-bund
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- unknownNCSC-2026-0238 [1.00] [M/H] Vulnerability fixed in Microsoft Dynamicsncsc-nl
- criticalCVE-2026-55944: Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to…nvd
More from Microsoft Security Response Center
- highCVE-2026-57992: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability2026-07-14
- mediumCVE-2026-59926: Mistune: XSS via unescaped class option in Admonition directive2026-07-14
- mediumCVE-2026-55003: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability2026-07-14
- highCVE-2026-42900: Microsoft Windows App Store Elevation of Privilege Vulnerability2026-07-14
- unknownCVE-2026-13867: Chromium: CVE-2026-13867 Inappropriate implementation in Geolocation2026-07-14