Blog
Critical NAV 2018 vulnerability: why your latest cumulative update is not the fix
If you still run Dynamics NAV 2018, there is one number worth checking today: the platform build of your service tier. Microsoft published a fix in July for a flaw that lets someone execute code on that server without an account, without a password, and without any help from your users. The patch exists and it is free to download. The catch is that the usual way of checking whether you already have it returns the wrong answer.
What the flaw actually is
CVE-2026-55944 was published on 14 July 2026. Microsoft rates it Critical with a CVSS base score of 9.8 out of 10, near the top of the scale. The mechanism is deserialization of untrusted data in the login path: an attacker sends a specially crafted login request to the service tier, and the server executes whatever the request carries. Microsoft’s own FAQ is blunt about the preconditions, stating that authentication and user interaction are not required.
That is what sets this apart from the average ERP advisory. There is no phishing step, no stolen password, no insider. Anything that can reach your NAV service tier over the network can try it. And because the code runs in the context of the NAV service account, it begins with whatever that account can reach, which in most installations is the whole company database.
Who is affected, precisely
The advisory is titled for the entire product family, “Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises)”, and its FAQ refers to a “Dynamics NAV or Business Central server”. That phrasing caused real confusion as the news circulated, with several people reading it as a Business Central problem.
The structured part of the advisory settles the question. Under known affected products there is exactly one entry: Microsoft Dynamics NAV 2018. No Business Central version appears anywhere in the record, and the advisory has not been revised since publication, so that list has not expanded either. NAV 2017 and earlier are not listed either.
Business Central on-premises versions from v13 to v23 sit in a grey area worth naming out loud. They are not listed as affected, but they are also out of support under the Modern Lifecycle policy, and Microsoft assesses and patches products that are in support. “Not listed” and “confirmed safe” are different statements. If you run one of those versions, the absence of an entry is not an all-clear.
The trap
Here is the part that catches people out. The fixed build is 11.0.50704.0. The newest cumulative update Microsoft publishes for NAV 2018 is CU 60, build 49618, from the end of 2022.
NAV 2018 left mainstream support in 2023 and now sits in extended support, which means security fixes only and no more regular cumulative updates. This correction therefore arrived as a standalone hotfix, outside the cadence most teams watch. A server on CU 60 is at the top of the published update list, is up to date by every ordinary measure, and is still vulnerable.
Anyone who answers “are we patched?” with “we are on the latest CU” will be wrong, and confidently so.
How to check your build
The platform build shows up in two places. In the Windows client, open Help and then About Microsoft Dynamics NAV, which displays the platform version. On the server itself, the file version of the NAV Server executable in the service tier installation folder carries the same number.
Compare whichever you find against 11.0.50704.0. Anything lower carries the flaw. NAV 2018 is version 11.0, incidentally, which is why the hotfix package is named NAV110.
Getting the fix
The download is titled NAV110 HF 11.0.50704.0, appeared on 6 July 2026 about a week ahead of the advisory itself, and sits in the Microsoft Download Center. It is public and requires no support contract, so a NAV 2018 owner without an active partner agreement can still get it.
It is not a small patch. The package is a single file of roughly 963 MB, a full DVD image, and Microsoft’s complete installation instruction reads “Run installer.” In practice the job is a platform update on the server: stop the service, replace the binaries, restart, and confirm everything came back up cleanly.
How big it gets depends on where you are now. The NAV Windows client is version matched to the service tier, so once the server moves to 11.0.50704.0, every workstation running that client needs the same platform build or it will refuse to connect. Depending on your current CU and on how many people work in the Windows client rather than the web client, a one server patch turns into a rollout to every desk. Count the machines before you pick a date.
If you would rather not do that yourself, we can do it for you. We check which build you are actually running, put the update through a restored copy of your environment first, and touch production only in an agreed window, workstation rollout included. You pay for the work it takes, with no monthly fee attached to it.
While you schedule it
Nobody is exploiting this yet. Microsoft’s advisory records the vulnerability as neither publicly disclosed nor exploited, its temporal score reflects unproven exploit code, and it has not appeared in the catalogue of known exploited vulnerabilities that CISA maintains. Microsoft does, however, rate it “Exploitation More Likely”.
Treat that as a window rather than a reprieve. The most effective interim step is making sure the service tier is not reachable from the internet at all. Its ports, 7046 to 7049 in a default installation, belong on an internal network or behind a VPN and should never be published. That is sound practice irrespective of this particular CVE, and it decides whether the advisory is merely important for your installation or urgent.
The clock behind the clock
This is the second unauthenticated code execution flaw to hit NAV in four years. CVE-2022-41127 was the previous one, and that time the fix reached every supported NAV and Business Central on-premises version at once.
NAV 2018 extended support ends in January 2028. Until then, security fixes will keep arriving the way this one did: irregularly, outside the channel most teams monitor, and easy to miss. After that date they stop, and a flaw of this severity would simply stay open in your system.
That is the strongest argument for planning a move, and a better one than any feature comparison. Not that NAV stopped working, but that the security floor underneath it has a published expiry date. If a move is already on your horizon, our NAV to BC upgrade checklist covers what decides the cost.
Unsure which build you are running, or what leaving NAV 2018 behind would involve? Tell us your story and we will work through it with you.