High severity8.8NVD Advisory· Published Apr 3, 2026· Updated Apr 9, 2026
CVE-2025-59710
CVE-2025-59710
Description
An issue was discovered in Biztalk360 before 11.5. Because of incorrect access control, any user is able to request the loading a DLL file. During the loading, a method is called. An attacker can craft a malicious DLL, upload it to the server, and use it to achieve remote code execution on the server.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.synacktiv.com/en/advisories/remote-code-execution-from-any-domain-account-in-biztalk360nvdThird Party Advisory
News mentions
0No linked articles in our index yet.