CVE-2026-67642: Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected SQL Server instance and be able to reach it over the network. The provided information does not indicate that unauthenticated attackers can exploit it.
What is the potential impact of successful exploitation?
Successful exploitation allows code execution on the affected SQL Server. The listed impact includes high confidentiality, integrity, and availability consequences.
Which deployments should be prioritized for review?
Review Microsoft SQL Server 2025, including SQL Server 2025 CU8, as well as deployments identified only as Microsoft SQL Server in the supplied software data. Network-accessible instances with authorized users should be prioritized.
Is there evidence that exploitation is occurring in the wild?
The supplied data marks exploit maturity as unknown. It does not provide evidence of active exploitation.