That sparse disclosure is the immediate story. A CVE designation establishes that Microsoft has acknowledged a security defect, but it does not establish that every Business Central tenant or on-premises deployment is exposed. At publication, Microsoft’s advisory labels the impact as information disclosure, which means the known risk is unauthorized viewing of data rather than code execution, privilege elevation, or service disruption. In an ERP product, however, the difference between “some information” and actionable business data can be substantial: Business Central commonly stores customer and vendor records, payment and posting data, inventory levels, pricing, documents, and operational notes.
No independent technical analysis, proof of concept, exploit report, NVD enrichment, or CVE Program record for CVE-2026-40375 was publicly indexed when this article was prepared. That means there is no defensible basis for claiming that the flaw is remotely exploitable, limited to authenticated users, connected to a specific Business Central feature, or fixed by a particular update. Those are the questions Microsoft needs to answer next.
Microsoft has not provided the triage fields administrators normally need
The absence of a CVSS vector is more consequential than the absence of a headline score. A score alone does not tell an administrator whether an attacker must already be a Business Central user, whether a malicious extension is involved, whether a crafted request can trigger the issue over the network, or whether data exposure is confined to a single company or tenant.
Microsoft’s public advisory also does not state whether Business Central Online is affected, whether the issue applies only to on-premises installations, or whether older release waves remain exposed. That gap matters because cloud and self-hosted customers have very different remediation paths. Microsoft can service Business Central Online centrally; on-premises customers must identify their installed version, obtain the corresponding package, test customizations and extensions, and complete the upgrade themselves.
The lack of a published exploitability assessment similarly matters. Microsoft’s Security Update Guide normally distinguishes vulnerabilities that are publicly disclosed or already exploited from those where exploitation is less likely. With no such data visible for CVE-2026-40375 at launch, organizations should avoid treating silence as evidence of either safety or active exploitation. The record currently supports a narrower conclusion: a confirmed Microsoft Business Central disclosure issue exists, and the public technical picture is incomplete.
August cumulative updates are available, but Microsoft does not map them to the CVE
Microsoft’s Business Central servicing documentation shows that August 2026 cumulative updates are now available across the three current on-premises release waves. The latest packages are:
- Business Central 2026 release wave 1, version 28.4, KB5123580, with Application Build 28.4.53241 and Platform Build 28.0.53152.
- Business Central 2025 release wave 2, version 27.10, KB5123579, with Application Build 27.10.53179 and Platform Build 27.0.53144.
- Business Central 2025 release wave 1, version 26.16, KB5123578, with Application Build 26.16.53177 and Platform Build 26.0.53077.
Microsoft says these packages supersede earlier updates, and that the latest cumulative update carries previous hotfixes forward. That is normal Business Central servicing behavior. It does not, by itself, prove that any of those three packages resolves CVE-2026-40375.
This is the documentation disconnect administrators should notice. The detailed release notes for Update 28.4 include platform and application fixes, including several access-control-adjacent changes such as enforcing attachment path rules, resolving multi-tenant access issues, preventing silent permission-set import failures, and correcting a license-related permission error. But the notes do not name CVE-2026-40375, do not use the term “information disclosure,” and do not identify any security fix as the remediation for Microsoft’s new advisory.
The same holds for the public Update 27.10 and Update 26.16 release materials: they identify ordinary product fixes, but do not provide an explicit CVE-2026-40375 mapping. Administrators should therefore install the current applicable cumulative update as a prudent baseline, while recording that the connection to this vulnerability has not been confirmed in Microsoft’s public release notes.
On-premises customers have a real operational decision
Business Central on-premises estates are rarely untouched vendor defaults. They often carry country-localized apps, partner-developed extensions, custom AL code, integrations with warehouse systems or payment providers, and bespoke permission sets. A broad instruction to “install the latest update” is appropriate but incomplete when the vendor has not said which versions are vulnerable or which update contains the security correction.
The practical response is to split the work into exposure confirmation and upgrade readiness.
First, inventory every Business Central environment and record its release wave, application build, platform build, deployment model, country localization, and installed extensions. Do not stop at production: sandboxes, disaster-recovery environments, test copies containing production data, and older partner-managed instances can all hold sensitive ERP information.
Second, verify whether any environment is already at the current August package for its release wave. For the supported 2025 and 2026 trains, that currently means version 26.16, 27.10, or 28.4. An environment on a July or earlier update has a straightforward maintenance case regardless of CVE-2026-40375: Microsoft’s cumulative-update model is designed for customers to remain current, and the latest package rolls prior hotfixes together.
Third, review the accounts and integration identities that can read across companies, access attachments, invoke APIs, run reports, or use administrative permission sets. Information-disclosure flaws often become more damaging where broad access has accumulated through convenience roles, stale service accounts, over-permissive API credentials, or extensions that expose data outside the expected user interface. This does not identify the root cause of CVE-2026-40375; Microsoft has not published one. It does reduce the damage an access-control failure can cause.
Finally, preserve meaningful logs now. Retention and review of Business Central audit data, Entra sign-in records, API activity, integration errors, and unusual attachment or export behavior are valuable if Microsoft later identifies a specific exploit path. Waiting until a technical advisory appears risks losing the period needed to determine whether unusual access preceded remediation.
Business Central Online customers need verification, not an assumed all-clear
For Business Central Online, the central question is whether Microsoft has already remediated the service. The Security Update Guide entry does not publicly say. Microsoft’s Business Central documentation tells Online administrators to use the Business Central administration center to check tenant update status, but a product-version check cannot confirm that a backend service-side mitigation was applied unless Microsoft publishes that relationship.
Organizations using Business Central Online should confirm their tenant’s current version, review Microsoft 365 and Dynamics service-health communications, and open a Microsoft support case if they require a written exposure determination for regulatory, contractual, or incident-response purposes. This is especially relevant for tenants holding financial records, personally identifiable information, payroll-related data, export-controlled inventory data, or documents synced from SharePoint and other connected services.
Partners should not tell customers that the August update “fixes CVE-2026-40375” unless Microsoft supplies the mapping. The current public evidence supports saying that Microsoft has acknowledged the vulnerability and that current cumulative updates exist. It does not support asserting that a given build is the official remediation threshold.
The missing version list is the security problem Microsoft still has to solve
Microsoft’s August 11 advisory gives Business Central administrators an identifier to track, but not a completed remediation instruction. That may change quickly as the Security Update Guide is revised, the CVE record is populated, or support articles are updated; vulnerability records routinely gain details after initial publication. As of August 11, however, the absence of affected-product data prevents accurate vulnerability-scanner rules and leaves organizations unable to distinguish exposed legacy deployments from unaffected current ones.
Treat CVE-2026-40375 as an active vendor-confirmed disclosure issue, bring on-premises environments to the latest supported cumulative update where change controls permit, and document the fact that Microsoft has not publicly connected those builds to the CVE. The next concrete milestone is a Microsoft-published affected-version and fixed-build list. Until then, any claim that a particular Business Central version is safe from this flaw is ahead of the public record.