CVE-2026-67380
massAuthenticated RCE via Heap Buffer Overflow in Microsoft SQL Server
Microsoft SQL Server contains a heap-based buffer overflow (CWE-122) that is reachable over the network by an authorized, low-privilege attacker. By sending crafted input to the database engine, the attacker can corrupt heap memory and trigger the overflow. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, reflected in the CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). All Microsoft SQL Server deployments are potentially in scope, though the affected version ranges are not specified in the available data. The flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS estimates only a 0.7% probability of exploitation within 30 days.
What to do: Because affected versions are not specified in this record, monitor Microsoft's advisory for CVE-2026-67380 and apply the SQL Server security update as soon as Microsoft publishes it. In the meantime, inventory SQL Server instances—especially any exposed to the internet on TCP 1433—and restrict network access, enforce strong authentication, and apply least-privilege login policies since exploitation requires valid (low-privilege) credentials. No exploitation in the wild is currently known, but EPSS and vendor advisories should be watched for updates.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.