CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-40375

highCVSS 6.5covered by 4 sourcesfirst seen 2026-08-11
A remote, authenticated attacker can exploit multiple vulnerabilities in Microsoft Dynamics 365 to execute arbitrary code or disclose confidential information.

CSIRTS triage

What
Multiple vulnerabilities in Microsoft Dynamics 365 enable arbitrary code execution and information disclosure.
Who is affected
Authenticated users of Dynamics 365 can exploit these vulnerabilities.
Urgency
High priority due to severity; requires authenticated access but enables code execution.
Action
Apply Microsoft security patches for Dynamics 365 immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-40375

Get an email if CVE-2026-40375 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-40375

CVE.org record

Embed the live status

CVE-2026-40375 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-40375 status](https://www.csirts.com/badge/CVE-2026-40375)](https://www.csirts.com/cve/CVE-2026-40375)