CVE-2026-67638
massHeap-Based Overflow in Microsoft SQL Server Enables Authenticated RCE
CVE-2026-67638 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server. An attacker holding valid, low-privileged credentials can trigger the flaw remotely over the network, with no user interaction required, per the CVSS vector (AV:N/AC:L/PR:L/UI:N). Successful exploitation allows code execution in the context of the SQL Server service, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Microsoft SQL Server deployments are potentially at risk, but the available advisory data does not specify which versions or edition ranges are affected. There is no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA KEV; EPSS estimates only a ~0.7% probability of exploitation within 30 days.
What to do: Monitor Microsoft's security advisory for CVE-2026-67638 and apply the security update it identifies as soon as it is released, since the affected version ranges are not yet listed in the available data. In the interim, reduce risk by restricting SQL Server's network exposure (e.g., limiting TCP port 1433/TDS access to trusted networks) and auditing which remote low-privileged SQL logins can connect, because exploitation requires valid credentials.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.