Microsoft Dynamics Advisory Splits Cloud and On-Prem Response

NCSC-NL said Microsoft fixed multiple Dynamics vulnerabilities on August 11, including CVE-2026-59118, the highest-rated issue at CVSS 9.3. The advisory covers Dynamics online, Dynamics 365 on-premises, Power Apps, and Business Central, with four CVEs total. Microsoft said the Power Apps flaw was already centrally mitigated, so it is listed for information rather than local action. The remaining issues can raise privileges, expose sensitive data, or allow code execution, and Microsoft released updates for the affected on-premises products. For hybrid Microsoft shops, the point is the split: cloud-managed fixes may already be in place while on-prem Dynamics systems still carry separate exposure. If your environment mixes both, the same advisory can mean no local work for one CVE and active patching for the others.

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: Microsoft Dynamics Advisory Splits Cloud and On-Prem Response

Sources