Critical ERP Vulnerabilities in Dynamics 365, SAP, and Oracle: What BC Partners Need to Know
If you implement, support, or sell Microsoft Dynamics 365 Business Central, the past month delivered a reminder that ERP platforms, not just endpoints and email are now a primary target for attackers. Four separate stories broke between late June and mid-July 2026, and one of them is about the exact product your clients run on. Here's what actually happened, verified against primary advisories and security reporting, and what it means for the conversations you should be having with clients.
Dynamics NAV and Business Central: a critical, unauthenticated RCE
The story most directly relevant to this audience: Microsoft's July 2026 Patch Tuesday (released July 14) included CVE-2026-55944, a critical remote code execution vulnerability affecting Microsoft Dynamics NAV and Dynamics 365 Business Central (On-Premises), with a CVSS score of 9.8.
The flaw is a deserialization-of-untrusted-data bug: an attacker can send a specially crafted login request to a reachable Dynamics NAV or Business Central server and execute arbitrary code no authentication and no user interaction required. Microsoft assessed exploitation as "more likely." In plain terms: any internet-reachable on-premises NAV or BC server that hasn't been patched is a live target.
This landed inside Microsoft's broader July release, which fixed 570 vulnerabilities total, including three zero-days.
What this means for partners: if you manage any on-premises Business Central or Dynamics NAV deployments, confirming the July 2026 cumulative update has been applied should be an immediate client conversation, not a "next maintenance window" item. Cloud-hosted BC tenants are not affected by this particular on-premises vulnerability, which is itself a talking point worth having with clients weighing on-prem vs. SaaS.