Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-88131 2026-10-08

CVE-2026-88131: Critical Deserialization Flaw in Microsoft Dataverse Enables Unauthenticated Remote Code Execution

"CVE-2026-88131 is a critical (CVSS 9.8) deserialization vulnerability in Microsoft Dataverse that an unauthorized attacker can use to execute code over a network."

CVE-2026-88131 is a critical (CVSS 9.8) deserialization vulnerability in Microsoft Dataverse that an unauthorized attacker can use to execute code over a network.

What Is It

The NVD description is: "Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network." The weakness is classified as CWE-502 (Deserialization of Untrusted Data). Microsoft ([email protected]) is the CVE source. The record was published on 2026-10-08, and NVD lists its status as "Received," so NVD has not finished its analysis yet.

Why It Matters

Microsoft rated the flaw 9.8, which is CRITICAL, using the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That vector means:

An attacker needs no credentials and no help from a user, and the attack is not complex. The exploitability subscore is 3.9 and the impact subscore is 5.9.

No CISA Known Exploited Vulnerabilities (KEV) entry was provided for this CVE. Active exploitation is not confirmed by KEV at this time.

What's Vulnerable

Microsoft tagged the CVE as an exclusively-hosted-service, which means the affected product runs as a service hosted by Microsoft. The supplied NVD data does not list specific CPEs.

Patch Status

The supplied records do not describe a specific patch, fixed version, or required customer action. There is no KEV entry, so no CISA remediation deadline or required action applies. The "exclusively-hosted-service" tag means Microsoft runs the affected service. Customers should check the MSRC advisory below for Microsoft's official guidance on remediation and on whether they need to do anything.

Sources