CVE-2026-78456: SQL Server Remote Code Execution Vulnerability
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Other sources
SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
The attacker must be authorized and able to reach the affected SQL Server over the network. No user interaction is required.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution. The provided severity vector indicates high impacts to confidentiality, integrity, and availability.
Which SQL Server releases are identified as affected?
The provided data identifies Microsoft SQL Server 2022 and Microsoft SQL Server 2022 CU 26. No information is provided about other versions, default configurations, mitigations, or detection methods.