Dynamics Nav
Vendor:
First CVE: Dec 12, 2018 · Active for 7 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dynamics Nav over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2018
7 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Dynamics Nav10 CVEs
50%
40%
10%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (10.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None5 (50.0%)
Unknown0 (0.0%)
Required5 (50.0%)
Privileges Required
Low7 (70.0%)
High1 (10.0%)
None2 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55944CRITICAL Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | Jul 14, 2026 | 9.8 | 40 | NO | NO |
CVE-2022-41127HIGH Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | Dec 13, 2022 | 8.5 | 28 | NO | NO |
CVE-2020-0905HIGH An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | Mar 12, 2020 | 8.0 | 24 | NO | NO |
CVE-2020-1022HIGH A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | Apr 15, 2020 | 8.0 | 23 | NO | NO |
CVE-2020-1018HIGH An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records a | Apr 15, 2020 | 7.5 | 23 | NO | NO |
CVE-2021-1724MEDIUM Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | Feb 25, 2021 | 6.1 | 22 | NO | NO |
CVE-2018-8651MEDIUM A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsof | Dec 12, 2018 | 5.4 | 21 | NO | NO |
CVE-2020-17133MEDIUM Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | Dec 10, 2020 | 6.5 | 20 | NO | NO |
CVE-2021-36946MEDIUM Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | Aug 12, 2021 | 5.4 | 19 | NO | NO |
CVE-2022-41066MEDIUM Microsoft Business Central Information Disclosure Vulnerability | Nov 9, 2022 | 4.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Dynamics Nav
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2018 | 8 | 7.2 | 3.7% | 0 | 0 |
| 2017 | 7 | 7.0 | 4.1% | 0 | 0 |
| 2016 | 6 | 7.3 | 4.7% | 0 | 0 |
| 2015 | 5 | 7.2 | 5.7% | 0 | 0 |
| 2013 | 2 | 8.0 | 8.8% | 0 | 0 |