CVE-2026-67636: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
Other sources
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized on the affected SQL Server instance and able to reach it over the network. The provided data does not indicate that unauthenticated attackers can exploit it.
What level of impact could successful exploitation have?
Successful exploitation may allow remote code execution. The severity vector indicates high potential impact to confidentiality, integrity, and availability, with impacts extending beyond the initially affected security scope.
Which SQL Server releases are listed as affected?
The listed software includes Microsoft SQL Server 2019, SQL Server 2022, and SQL Server 2025, including SQL Server 2019 CU32, SQL Server 2022 CU26, and SQL Server 2025 CU8.
Does exploitation require user interaction?
No. The severity vector specifies UI:N, indicating no user interaction is required once an attacker has the necessary authorization and network access.