CVE-2026-67643: Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authorized and able to reach the SQL Server instance over the network. No user interaction is required.
Which deployments should be prioritized for review?
Review Microsoft SQL Server 2025, including CU8, and Microsoft SQL Server 2022, including CU26, as these are the software entries identified for this vulnerability.