CVE-2026-67384
massInteger Overflow Remote Code Execution in Microsoft SQL Server
CVE-2026-67384 is an integer overflow or wraparound flaw (CWE-190, listed alongside CWE-122 memory corruption) in Microsoft SQL Server, rated High severity at CVSS 8.8. It is triggered over the network by an authorized attacker: the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates that any account with the ability to connect to and send requests to the SQL Server service can reach the vulnerable code path, with no user interaction required. Successful exploitation yields remote code execution in the context of the SQL Server service, with high impact on confidentiality, integrity, and availability. Any organization running Microsoft SQL Server is potentially affected, although the source data does not specify which version ranges are impacted. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a modest 0.6% probability of exploitation within 30 days, so no exploitation is known.
What to do: Apply Microsoft's security update for CVE-2026-67384 as soon as it is released, and check Microsoft's advisory for the exact affected versions since they are not listed in this data. Until patched, limit network exposure of SQL Server instances (firewall/NSG rules, VPN-only or internal-only access) and review which accounts hold remote login rights, since exploitation requires authorized credentials. Monitor Microsoft communications for updated exploit or exploitation status.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.