CVE-2026-77486: Microsoft SQL Server Remote Code Execution Vulnerability
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2130.4Patch KB5122775 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3550.4Patch KB5122774
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable over a network with low attack complexity and requires no prior privileges. User interaction is required.
What is the potential impact if exploitation succeeds?
Successful exploitation could allow code execution and affect the confidentiality, integrity, and availability of the SQL Server system.
Which SQL Server releases are identified as affected?
The listed affected software includes Microsoft SQL Server 2017, SQL Server 2017 CU 31, SQL Server 2019, and SQL Server 2019 CU 32.