CVE-2026-67639
massHeap-Based Buffer Overflow in Microsoft SQL Server Allows Authenticated RCE
CVE-2026-67639 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server, assigned by Microsoft and rated 8.8 (High) with a network-exploitable, low-complexity attack vector. An attacker who already holds some valid credentials against the SQL Server instance (CVSS 'privileges required: low') can trigger the flaw remotely by sending crafted input that overflows a heap buffer, with no user interaction required. Successful exploitation yields code execution in the context of the SQL Server service, with high impact on confidentiality, integrity, and availability - effectively turning a low-privileged database login into server-level code execution. Any Microsoft SQL Server deployment covered by Microsoft's advisory is affected; the available data does not specify affected versions or editions. No exploitation has been reported so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at 0.7% (median percentile).
What to do: Apply Microsoft's security update for CVE-2026-67639 to all SQL Server instances; since this data does not include build numbers, consult Microsoft's advisory to map your editions/versions to the correct patch. Prioritize instances reachable from untrusted networks, restrict TCP/1433 exposure to trusted sources, and review which accounts can authenticate to SQL Server, because exploitation requires valid credentials. No public PoC or in-the-wild exploitation is known, so standard patch cadence is acceptable, but re-check KEV/EPSS status for changes.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019, sql server 2022, sql server 2025
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.