CVE-2026-67385
massUse-After-Free RCE in Microsoft SQL Server
CVE-2026-67385 is a use-after-free memory-corruption flaw (CWE-416) in Microsoft SQL Server that allows an authorized attacker to execute arbitrary code over a network. An attacker with valid low-privilege credentials and network reachability to the SQL Server instance can send requests that trigger the freed-memory condition and gain code execution in the context of the SQL Server service. Successful exploitation yields high confidentiality, integrity, and availability impact on the target server (CVSS 3.1: 8.8). All organizations running affected SQL Server versions are potentially exposed, though the flaw requires authentication rather than anonymous access. There is currently no known public proof-of-concept, it is not listed in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 0.5%.
What to do: Consult Microsoft's advisory to identify the affected SQL Server versions/builds and apply the corresponding security update, prioritizing instances that are internet-exposed or reachable by broadly held low-privilege accounts. In the interim, restrict network access to SQL Server ports, enforce least-privilege authentication, and limit which accounts can connect remotely. Monitor Microsoft's guidance for exploitation updates, since a patch (or attacker interest) could change the picture quickly.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in SQL Server allows an authorized attacker to execute code over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.