DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-42898PUBLISHED: 2026-05-12
CRITICALCVE-2026-42898

Microsoft Dynamics 365 On-Premises Authenticated Code Injection RCE (Scope Change)

VENDOR: Microsoft//PRODUCT: Microsoft Dynamics 365 (on-premises)
9.9
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An improper control of code generation (CWE-94) vulnerability in Microsoft Dynamics 365 on-premises allows any low-privileged authenticated attacker to execute arbitrary code over the network by modifying the saved state of a process session in Dynamics CRM. The vulnerability is rare in that it carries a scope change flag, meaning successful exploitation can impact systems beyond the vulnerable component itself — a significant blast-radius indicator for enterprises running Dynamics CRM with connected business workflows and customer data. No user interaction is required. Microsoft urges immediate customer action (unlike several Azure-side fixes this month handled server-side).

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSMicrosoft Dynamics 365 on-premises versions prior to May 2026 Patch Tuesday update
  • Microsoft MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898
  • CrowdStrike May 2026 Patch Tuesday: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-may-2026/
  • SC World: https://www.scworld.com/news/patch-tuesday-no-zero-days-among-137-microsoft-cves-4-word-rces
  • The Register: https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/
  • Security Boulevard: https://securityboulevard.com/2026/05/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn