Dynamics NAV 2018's Critical CVE: Patch It, But Let's Talk About What It Actually Means

Dynamics NAV 2018's Critical CVE: Patch It, But Let's Talk About What It Actually Means

Microsoft published an advisory for Dynamics NAV 2018 regarding CVE-2026-55944 on July 14, 2026. It has a CVSS score of 9.8 out of 10.

It does not require a login. Nobody needs to click anything. An attacker can send a specially crafted authentication request to a NAV 2018 service tier and potentially get the server to execute code.

If you are affected, you should install the security upgrade.

How worried should you be right now?

There is no publicly available exploit, it isn’t on CISA’s Known Exploited Vulnerabilities list, and there are no reports of it being used in the wild.

At this point, the people most likely to be trying to reproduce it are security researchers and people who work with NAV and want to understand what Microsoft fixed. There isn’t evidence that this is being actively exploited.

The bigger issue is what happens if a malicious actor does exploit it.

This isn’t a web server where somebody changes your homepage, and you can clean it up. NAV is in the middle of your accounting, purchasing, shipping, inventory, and everything else you need to operate your business.

The odds may be low right now. The consequences are not.

I think about this the same way I think about keeping Mylar blankets in the car. I don’t expect to get stranded somewhere where I need one. They are cheap, but also valuable in an emergency.

This security upgrade is basically cheap insurance.

Is your NAV service tier reachable directly from the internet?

There’s one thing I would check before getting too worked up about the 9.8 score.

Is your NAV service tier reachable directly from the internet?

If yours is already behind a VPN, your practical risk is considerably lower. To exploit the system, someone would need to be inside your VPN.

If your NAV system is on a public IP, I would change that first, whether there’s a known exploit or not.

This is specifically a Dynamics NAV 2018 issue

There’s also been some confusion around the wording of Microsoft’s advisory.

Business Central appears in some of the advisory language, but supported versions of Business Central are not listed as affected.

If you’re running an old, unsupported version of Business Central on-premises, “not on the list” doesn’t mean you’re safe. But this advisory is primarily about NAV, not Business Central.

What I would actually do

If this were my Dynamics NAV environment, I wouldn’t shut everything down and declare an emergency.

I would:

  1. Check whether the NAV service tier is exposed to the internet.
  2. Fix that immediately if it is.
  3. Check the NAV platform build.
  4. If it’s below 11.0.50704.0, get the security upgrade into a test environment.
  5. Test the clients and anything else that depends on the NAV service tier.
  6. Upgrade production.

If you’re already planning a move to Business Central, this is one more reason to keep that project moving.

And if you’re not sure which NAV build you’re running or whether your service tier is exposed, ArcherPoint by Cherry Bekaert can help you check.

Stay Informed

Subscribe to Communications

"*required" indicates required fields

This field is for validation purposes and should be left unchanged.
Subscription Options
By subscribing you are consenting to receiving emails from ArcherPoint and agreeing to the storing & processing of your personal data as described in our Privacy Policy. You can can unsubscribe at any time.
This field is hidden when viewing the form