CVE-2026-68785: Microsoft SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access the affected SQL Server instance and be able to reach it over the network. The available data does not indicate that unauthenticated attackers can exploit it.
What is the expected impact of successful exploitation?
Successful exploitation can allow code execution on the affected SQL Server. The supplied scoring data indicates an availability impact, while confidentiality and integrity impacts are listed as none.
Which SQL Server releases are identified as affected?
The affected software list includes Microsoft SQL Server 2017, 2019, 2022, and 2025, including SQL Server 2017 CU 31, SQL Server 2019 CU 32, SQL Server 2022 CU 26, and SQL Server 2025 CU8.
Does exploitation require user interaction or complex attack conditions?
No user interaction is required, and the attack complexity is rated low. Exploitation still requires high privileges and network access to the SQL Server instance.