CVE-2026-67641: Microsoft SQL Server Denial of Service Vulnerability
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
Other sources
Microsoft SQL Server Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized and able to reach the SQL Server instance over the network. No user interaction is required.
What is the impact of successful exploitation?
Successful exploitation can deny service on the affected SQL Server instance. The provided information does not indicate confidentiality or integrity impact.
Which SQL Server releases are identified as affected?
The listed software includes Microsoft SQL Server 2022, SQL Server 2022 CU 26, SQL Server 2025, and SQL Server 2025 CU8.