ZeroHour

CVE-2026-32176

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
sql server 2016, sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-89
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.