CVE-2026-67376: Microsoft SQL Server Denial of Service Vulnerability
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
Other sources
Microsoft SQL Server Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable over the network. It requires no privileges and no user interaction.
What is the expected impact if exploitation succeeds?
Successful exploitation can deny service in SQL Server. The provided impact information identifies availability as affected, with no stated confidentiality or integrity impact.
Which SQL Server releases are identified as affected?
The listed software includes SQL Server 2017, SQL Server 2019, SQL Server 2022, and SQL Server 2025, including SQL Server 2017 CU 31, SQL Server 2019 CU 32, SQL Server 2022 CU 26, and SQL Server 2025 CU8.