CVE-2026-67636
Microsoft SQL Server Remote Code Execution Vulnerability
Description
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
In plain language
AI Act nowThis is a Microsoft SQL Server bug that can allow someone on the network to run malicious code, but it’s mainly a risk for businesses that are reachable and have a realistic path for an attacker to get authorized access; apply the specific SQL Server updates listed in this advisory.
Microsoft SQL Server has a remote code execution weakness (CWE-125) triggered through an out-of-bounds read in the SQL Server network-accessible functionality; affected SQL Server versions should be updated to the fixed cumulative update/GDR build numbers provided.
What to do now
- Check which Microsoft SQL Server edition and build you run (for example, whether it’s 2019 CU 32 / 2019 GDR / 2022 CU 26 / 2022 GDR / 2025 CU8 / 2025 x64 GDR).
- If your build matches any affected level, plan an update to the fixed build for your exact branch: 15.0.4490.9 (2019 CU 32), 15.0.2190.7 (2019 GDR), 16.0.4275.2 (2022 CU 26), 16.0.1200.5 (2022 GDR), 17.0.4085.5 (2025 CU8), or 17.0.1135.8 (2025 x64 GDR).
- Test the update in a staging environment (if you have one), then roll it out to production during your next maintenance window.
- After updating, verify the server reports the expected fixed build number and review authentication and SQL server access logs for unusual activity around the time of any suspected probing.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-67636 and every CVE in our database. Create a free account — no credit card required.
Create Free Account