A newly disclosed security vulnerability in Microsoft Dynamics NAV requires immediate action. Attackers can exploit the flaw over the network without signing in and without any user having to click or confirm anything. Affected installations should be updated without delay. This is also the right moment to begin the permanent move to the Business Central Cloud.

Microsoft published the critical vulnerability CVE-2026-55944 on 14 July 2026. The cause is the unsafe processing of untrusted data. As a result, an unauthenticated attacker can execute code over the network on an affected Dynamics NAV server. The CVSS score is 9.8 out of 10 points.

According to the published information, a specially crafted login request can be enough to exploit the vulnerability. No prior sign-in is required. Involvement by an employee, such as opening an attachment or clicking a link, is not needed either.

That sets CVE-2026-55944 apart from many classic phishing or malware attacks. A reachable, unpatched server can be attacked directly.

The key facts about CVE-2026-55944

Severity: Critical
CVSS score: 9.8 out of 10
Attack vector: Over the network
Sign-in required: No
User interaction required: No
Possible impact: Execution of arbitrary code on the affected system
Cause: Deserialization of untrusted data, CWE-502
Affected versions: Microsoft Dynamics NAV below version 11.0.50704.0 (all versions are affected, for example NAV2009 – NAV2017 as well)
Patched version: 11.0.50704.0 or newer

This rating means that an attack can be carried out remotely, has low attack complexity, and requires no existing user privileges. The potential impact on confidentiality, integrity, and availability is rated high in each case.

Which systems are affected?

In its official list of affected products, Microsoft currently names Microsoft Dynamics NAV in versions from 1.0 up to but not including 11.0.50704.0.

Companies should not rely on the product name shown in the client alone. What matters is the specific build version of the installed server components.

Why is this vulnerability so dangerous?

In many attacks, a user first has to open a link, run an attachment, or enter their credentials on a fake page. With CVE-2026-55944, no such preparatory steps are required.

According to the CVSS rating, an attacker needs:

  • no valid NAV credentials,
  • no existing user privileges,
  • no interaction from an employee,
  • and no local access to the server.

If the attacker can reach the vulnerable service over the network, a crafted request can lead to code execution. Microsoft rates the potential loss of confidentiality as high, and the impact on data integrity and system availability as well.

For an ERP system, this is particularly serious. Dynamics NAV is often closely tied to financial accounting, inventory management, production, purchasing, sales, and other business-critical processes. A compromise of the server can therefore reach far beyond a single technical service.

What companies need to do now

1. Determine the installed build version

Check without delay which Dynamics NAV version is installed on all server instances. What counts is not only the version of the Windows client, but in particular the version of the server components in use.

If the version is below 11.0.50704.0, Microsoft considers the installation to be affected by CVE-2026-55944.

2. Apply the security update immediately

Affected systems must be updated to version 11.0.50704.0 or a newer, patched version. Before installing it, check whether custom modifications, Add-ons, or connected systems are affected by the update.

An ongoing or planned migration project is no reason to postpone the update. Even if the cloud migration has already started, the existing NAV environment has to stay protected until it is finally shut down.

3. Check how the NAV services can be reached

Check which networks the affected services are reachable from. External access that is not needed should be restricted or temporarily blocked. Systems that are reachable directly or indirectly over the internet need particular attention.

Restricting access does not replace the security update. It can, however, reduce the risk until the update has been applied successfully.

4. Review logs and server behavior

Check server and application logs for unusual sign-in requests, unexpected processes, unknown user accounts, modified files, or conspicuous network connections.

You should also verify that current backups exist that are stored separately and can actually be restored.

5. Commit to a firm start for the move off the legacy version

The patch closes the vulnerability that is currently known. It does not solve the underlying problem of an older OnPremise installation, where updates, operating systems, SQL Server, custom Extensions, and external interfaces have to be maintained in-house on an ongoing basis.

CVE-2026-55944 should therefore not be viewed as an isolated technical incident. The security advisory is a concrete reason to carry out a modernization that has already been postponed for some time.

Patch or migrate? The answer is: both

In the short term, the affected NAV version has to be updated. There is no responsible way around that.

In parallel, review whether running an older NAV infrastructure still makes sense. When you move to Business Central Online, updates are delivered continuously through the cloud service. Administrators can define maintenance windows and schedule updates within the intended time frames. This removes the familiar upgrade backlog, where companies stay on an old major version for years.

A cloud solution is not inherently free of security risks either. The operating model does change significantly: the underlying platform and the regular delivery of updates are no longer organized entirely in your own server environment.

To Business Central Cloud within two to four weeks

With DataMigrate Pro, IO Integrated enables direct migration from Dynamics NAV, Navision, and older Business Central versions to the latest version of Microsoft Dynamics 365 Business Central.

Unlike a classic technical upgrade, the database does not have to be raised step by step through several so-called jump versions. The data can be transferred directly into the new Business Central environment.

DataMigrate Pro supports, among other things:

  • master data and setup data,
  • open and posted documents,
  • general ledger, customer, and vendor entries,
  • custom tables and fields,
  • delta migrations and follow-up synchronizations,
  • parallel operation of NAV and Business Central,
  • and a predictable switchover with minimal business interruption.

Depending on data volume, customizations, Add-ons, and organizational preparation, the move with DataMigrate Pro can be completed within two to four weeks. The existing NAV environment and Business Central can run in parallel during the migration, and data can be synchronized repeatedly.

Why now is the right time to make the move

Many companies still run Dynamics NAV reliably in day-to-day business. That is often exactly why a migration keeps being postponed. As long as the system works, the pressure to act seems low.

CVE-2026-55944 shows how quickly that assessment can change.

With each additional year, dependencies on older server operating systems, SQL versions, custom modifications, and Extensions that are no longer maintained typically grow. At the same time, it becomes harder to respond to new security requirements at short notice.

A planned migration is almost always better than a switch forced under time pressure after a security incident.

Secure NAV now and start the cloud migration

Are you running Microsoft Dynamics NAV 2018 (or earlier), or are you unsure about your build version?

Then you should act now:

Have your installed version checked, apply the required security update, and start the migration to Business Central Cloud in parallel. With DataMigrate Pro, the direct move can be completed within two to four weeks, depending on the scope of the project.

Sascha Marquardt
About the author

Sascha Marquardt

Responsible for the partner programme, the licensing business and commercial project delivery.