ZeroHour

CVE-2026-67638

mass

Heap-Based Overflow in Microsoft SQL Server Enables Authenticated RCE

CVSS 3.1
8.8 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-67638 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server. An attacker holding valid, low-privileged credentials can trigger the flaw remotely over the network, with no user interaction required, per the CVSS vector (AV:N/AC:L/PR:L/UI:N). Successful exploitation allows code execution in the context of the SQL Server service, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Microsoft SQL Server deployments are potentially at risk, but the available advisory data does not specify which versions or edition ranges are affected. There is no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates only a ~0.7% probability of exploitation within 30 days.

What to do: Monitor Microsoft's security advisory for CVE-2026-67638 and apply the security update it identifies as soon as it is released, since the affected version ranges are not yet listed in the available data. In the interim, reduce risk by restricting SQL Server's network exposure (e.g., limiting TCP port 1433/TDS access to trusted networks) and auditing which remote low-privileged SQL logins can connect, because exploitation requires valid credentials.

Affected
Microsoft SQL Server
Estimated exposure
massmillions of installations (SQL Server is among the most widely deployed enterprise relational databases) — Microsoft SQL Server is one of the most widely deployed enterprise database platforms with an install base in the millions of servers worldwide, so the potentially affected population plausibly exceeds one million deployments even though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sql server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.