CVE-2026-55944Critical
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Assessment
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- Severity
- Critical
- CVSS base score
- 9.8CVSS:3.1/
AV:N/ AC:L/ PR:N/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Remote Code Execution
- EPSS, next 30 days
- 1.5%Higher than 73.8% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation More Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Dynamics NAV
- Weakness
- CWE-502: Deserialization of Untrusted Data
- Issued by
- Microsoft
- Published
- 14 Jul 2026 · July 2026
- Last revised
- 14 Jul 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Microsoft Dynamics1 affected product
- Microsoft Dynamics NAV 2018