CVE-2026-40375HighCVSS 6.5

Microsoft Dynamics Business Central Information Disclosure Vulnerability

Published
August 14, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

🎯 Affected products4

  • Microsoft Dynamics 365 Business Central 2024 Release Wave 2
  • Microsoft Dynamics 365 Business Central 2026 Release Wave 1
  • Microsoft Dynamics 365 Business Central Release Wave 1 2025
  • Microsoft Dynamics 365 Business Central Release Wave 2 2025

✅ Remediation

KB5100263 (Security Update) — fixed build 26.0.50788 KB5100266 (Security Update) — fixed build 28.0.50938 KB5100265 (Security Update) — fixed build 27.0.50789

🔗 References (4)