ZeroHour

CVE-2026-67631

mass

Heap-Based Buffer Overflow in Microsoft SQL Server Allows Authenticated RCE

CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-67631 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server, rated 8.8 (High) on CVSS 3.1 by Microsoft. A remote attacker who already holds valid low-privileged credentials - an "authorized attacker" per Microsoft - can send crafted input to the database engine over the network to overflow a heap buffer, with no user interaction required. Successful exploitation runs code in the context of the SQL Server process and carries high impact on confidentiality, integrity, and availability, typically meaning full compromise of the affected service. Organizations running Microsoft SQL Server are in scope; the available data does not specify affected version ranges, and fixes were distributed through Microsoft's September 2026 Patch Tuesday, per related Patch Tuesday coverage. There are no known public exploits, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.6% (roughly median) probability of exploitation within 30 days.

What to do: Install the SQL Server security updates from Microsoft's September 2026 Patch Tuesday on all instances, prioritizing any that are internet-facing or reachable on TCP 1433. Because exploitation requires an authorized account, audit low-privileged SQL logins and application service accounts, restrict network exposure of database ports, and monitor using the Snort signatures released alongside the September 2026 updates.

Affected
Microsoft SQL Server
Estimated exposure
masslikely on the order of 1M+ deployed SQL Server instances worldwide, with 100,000+ internet-exposed — SQL Server is one of the most widely deployed enterprise relational databases, and public internet scans have historically shown on the order of 100,000+ instances listening on TCP 1433, though exploitation here additionally requires valid…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.

Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.

Cisco Talos · 7d agoAdvisory in the wildCVE-2026-81963CVE-2026-85880CVE-2026-69676+27 CVEs