ZeroHour

CVE-2026-67636

mass

Out-of-Bounds Read Leading to RCE in Microsoft SQL Server

CVSS 3.1
8.5 high
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-67636 is an out-of-bounds read vulnerability (CWE-125) in Microsoft SQL Server, rated 8.5 (High) with a network attack vector. An attacker who already holds low-privileged (authorized) access to the SQL Server can send crafted network requests that trigger the faulty memory read, which can be leveraged to execute code on the server; the changed-scope metric indicates the impact can extend beyond the isolated component to the wider system. Successful exploitation yields high impact to confidentiality, integrity, and availability of the SQL Server environment. All organizations running affected Microsoft SQL Server builds are potentially affected, with specific version ranges listed in Microsoft's advisory. Exploitation status: no public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for SQL Server referenced in the advisory for CVE-2026-67636 as part of your next patch cycle, checking installed SQL Server builds against Microsoft's affected-version list. Until patched, reduce exposure by restricting network access to SQL Server listeners (firewall/NSG rules), minimizing the number of low-privileged accounts with login rights, and monitoring for anomalous query activity. No public exploit is known, so there is no immediate pressure, but the High CVSS and RCE impact make prioritized patching advisable.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of SQL Server installations worldwide, though only those reachable by an attacker with valid low-privileged credentials are practically at risk — Microsoft SQL Server is one of the most widely deployed enterprise relational databases, with an install base in the millions of instances across enterprises, although the low-privilege requirement limits exploitation to attackers who…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.