CVE-2026-67636
massOut-of-Bounds Read Leading to RCE in Microsoft SQL Server
CVE-2026-67636 is an out-of-bounds read vulnerability (CWE-125) in Microsoft SQL Server, rated 8.5 (High) with a network attack vector. An attacker who already holds low-privileged (authorized) access to the SQL Server can send crafted network requests that trigger the faulty memory read, which can be leveraged to execute code on the server; the changed-scope metric indicates the impact can extend beyond the isolated component to the wider system. Successful exploitation yields high impact to confidentiality, integrity, and availability of the SQL Server environment. All organizations running affected Microsoft SQL Server builds are potentially affected, with specific version ranges listed in Microsoft's advisory. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for SQL Server referenced in the advisory for CVE-2026-67636 as part of your next patch cycle, checking installed SQL Server builds against Microsoft's affected-version list. Until patched, reduce exposure by restricting network access to SQL Server listeners (firewall/NSG rules), minimizing the number of low-privileged accounts with login rights, and monitoring for anomalous query activity. No public exploit is known, so there is no immediate pressure, but the High CVSS and RCE impact make prioritized patching advisable.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.