🟠 High | Source: Microsoft Security Response Center
CVE-2026-40417 is an elevation of privilege vulnerability affecting Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. This update revises the affected build numbers but introduces no new technical findings. Organisations running Business Central should verify whether their deployed version falls within the updated scope.
Security Architect’s Take: Review the updated build numbers published by Microsoft to confirm whether your Dynamics 365 Business Central environment is affected, and ensure automatic updates are enabled or apply the relevant patch manually if running a self-managed deployment.
Original advisory: CVE-2026-40417 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability