SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47646

CRITICAL · CVSS 9.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

Dynamics 365 Customer Voice is vulnerable to a critical cross-site scripting (XSS) flaw that allows unauthorized attackers to inject malicious scripts, potentially leading to user impersonation and data theft. Organizations utilizing this platform should prioritize immediate remediation efforts to mitigate the risk of exploitation and protect sensitive user information. Given the high severity rating, all users of Dynamics 365 Customer Voice must assess their exposure and apply necessary security updates promptly.

CVE
CVE-2026-47646
Severity
CRITICAL
CVSS
9.3
EPSS
0.27%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)