Skip to content
CVSS 9.3 · CRITICAL

CVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

View on NVD

Analysis

Microsoft Dynamics 365 (Online) contains a critical Server-Side Request Forgery (SSRF) vulnerability. This flaw allows unauthorized attackers to perform network spoofing, which could lead to unauthorized access to internal services or sensitive data within the cloud environment. Organizations using Dynamics 365 should verify their instances are updated to the latest secure version.

Severity

Score: 9.3(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: REQUIRED
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-918

EPSS

Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 16.2%
EPSS: 2026-05-06

Affects

microsoft:dynamics_365

Technical description

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

Published: 4/23/2026, 10:16:35 PM
Last modified: 5/5/2026, 2:10:29 PM

References

HomeEventsBlogResourcesTeam