CVE-2026-55944: Critical Vulnerability in Microsoft Dynamics NAV – Take Action Immediately!

A newly disclosed security vulnerability in Microsoft Dynamics NAV requires immediate action. Attackers can exploit the vulnerability over the network without having to log in and without requiring a user to click or confirm anything. Affected installations should be updated immediately. At the same time, now is the right time to begin the permanent transition to the Business Central Cloud.

On July 14, 2026, Microsoft disclosed the critical security vulnerability CVE-2026-55944. The cause is the insecure processing of untrusted data. An unauthenticated attacker can exploit this vulnerability to execute code over the network on an affected Dynamics NAV server. The CVSS score is 9.8 out of 10.

According to the published information, a specially crafted login request alone may be sufficient to exploit the vulnerability. No prior login is required. Nor is any interaction by an employee—such as opening an attachment or clicking a link—necessary.

This is what sets CVE-2026-55944 apart from many traditional phishing or malware attacks. An accessible, unpatched server can be attacked directly.

Key Facts About CVE-2026-55944

Severity: Critical
CVSS score: 9.8 out of 10
Vector of attack: Via the network
Registration required: No
User interaction required: No
Potential impact: Execution of arbitrary code on the affected system
Cause: Deserialization of untrusted data, CWE-502
Affected versions: Microsoft Dynamics NAV versions prior to 11.0.50704.0 (All versions, including NAV 2009 through NAV 2017, are affected)
Supported version: 11.0.50704.0 or later

This classification means that an attack can technically be carried out remotely, is relatively simple to execute, and does not require any prior user privileges. The potential impact on confidentiality, integrity, and availability is rated as high in each case.

Which systems are affected?

In the official list of affected products, Microsoft currently lists Microsoft Dynamics NAV versions 1.0 and earlier, as well as versions prior to 11.0.50704.0.

Companies should not rely solely on the product name displayed in the client. What matters is the specific build version of the installed server components.

Why is this security vulnerability so dangerous?

In many attacks, a user must first open a link, run an attachment, or enter their login credentials on a fake page. With CVE-2026-55944, such preliminary steps are not required.

According to the CVSS score, an attacker needs:

  • No valid NAV credentials,
  • No user permissions available,
  • no interaction by an employee,
  • and no local access to the server.

If an attacker can access the vulnerable service over the network, a specially crafted request could lead to code execution. Microsoft rates both the potential loss of confidentiality and the impact on data integrity and system availability as high.

This is particularly serious for an ERP system. Dynamics NAV is often closely integrated with financial accounting, inventory management, manufacturing, purchasing, sales, and other business-critical processes. A compromise of the server can therefore have implications that extend far beyond a single technical service.

What Companies Need to Do Now

1. Determine the installed build version

Check immediately which version of Dynamics NAV is installed on all server instances. It is not only the version of the Windows client that matters, but especially the version of the server components in use.

If the version is lower than 11.0.50704.0, the installation is affected by CVE-2026-55944, according to Microsoft.

2. Install the security update immediately

Affected systems must be updated to version 11.0.50704.0 or a newer, secure version. Before installation, you should verify whether any customizations, add-ons, or integrated systems will be affected by the update.

An ongoing or planned migration project is no reason to postpone the update. Even if the cloud migration has already begun, the existing NAV environment must be protected until it is finally decommissioned.

3. Check the availability of NAV services

Check which networks can access the affected services. Unnecessary external access should be restricted or temporarily blocked. Systems that are accessible directly or indirectly via the Internet require special attention.

Restricting access does not replace the security update. However, it can reduce the risk until the update is successfully installed.

4. Check Logs and Server Behavior

Check server and application logs for unusual login requests, unexpected processes, unknown user accounts, modified files, or suspicious network connections.

In addition, it should be verified whether up-to-date, separately stored, and actually recoverable data backups are available.

5. Initiate the mandatory migration from the old version

The patch addresses the currently known security vulnerability. However, it does not resolve the underlying issue with older on-premises installations, where updates, operating systems, SQL Server, custom extensions, and external interfaces must be maintained manually on an ongoing basis.

CVE-2026-55944 should therefore not be viewed merely as an isolated technical incident. This security advisory provides a concrete reason to finally implement a modernization that has been postponed for some time.

Patch or migrate? The answer is: both

In the short term, the affected NAV version must be updated. There is no responsible way around this.

At the same time, you should assess whether it still makes sense to continue operating an older NAV infrastructure. When switching to Business Central Online, updates are continuously delivered via the cloud service. Administrators can set maintenance windows and schedule updates within the designated time periods. This eliminates the traditional upgrade backlog, in which companies remain on an old major version for years.

Even a cloud solution is not inherently free of security risks. However, the operating model changes significantly: The underlying platform and the regular provision of updates are no longer managed entirely within the company’s own server environment.

Get started with Business Central Cloud in two to four weeks

With DataMigrate Pro, IO Integrated enables the direct migration of Dynamics NAV, Navision, and older versions of Business Central to the latest version of Microsoft Dynamics 365 Business Central.

Unlike a traditional technical upgrade, the database does not need to be upgraded incrementally through several so-called “jump versions.” The data can be transferred directly to the new Business Central environment.

DataMigrate Pro supports, among other things:

  • Master data and configuration data,
  • open and posted documents,
  • Asset, accounts receivable, and accounts payable items,
  • custom tables and fields,
  • Delta migrations and resynchronizations,
  • Running NAV and Business Central in parallel,
  • as well as a predictable transition with minimal disruption to operations.

Depending on the volume of data, customizations, add-ons, and organizational preparation, the migration using DataMigrate Pro can be completed within two to four weeks. The existing NAV environment and Business Central can be run in parallel during the migration, and data can be synchronized repeatedly.

Why Now Is the Right Time to Make the Switch

Many companies still rely on Dynamics NAV for their day-to-day operations. This is precisely why migrations are often postponed time and again. As long as the system is working, there seems to be little urgency to take action.

CVE-2026-55944 shows just how quickly this assessment can change.

With each passing year, dependencies on older server operating systems, SQL versions, customizations, and extensions that are no longer supported typically increase. At the same time, it becomes more difficult to respond quickly to new security requirements.

A planned migration is almost always better than a rushed transition forced by a security incident.

Secure NAV Now and Start Your Cloud Migration

Are you running Microsoft Dynamics NAV 2018, or are you unsure of your build version?

Then you should act now:

Have your installed version checked, apply the necessary security update, and begin the migration to Business Central Cloud at the same time. With DataMigrate Pro, the direct migration can be completed within two to four weeks, depending on the scope of the project.