ZeroHour

CVE-2026-68786

mass

Heap Buffer Overflow in Microsoft SQL Server Enables Authenticated RCE

CVSS 3.1
8.8 high
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-68786 is a heap-based buffer overflow (CWE-122) in Microsoft SQL Server that can be triggered remotely by sending crafted input to the service. The attacker must be an authorized user with low privileges, so valid credentials are required to reach the vulnerable code path. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N). Organizations running Microsoft SQL Server are affected; specific version ranges are not included in the available data and should be confirmed in Microsoft's advisory. Exploitation has not been observed in the wild, the issue is not in CISA's KEV catalog, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at roughly 0.5% (41st percentile).

What to do: Check Microsoft's advisory for CVE-2026-68786 to identify affected SQL Server versions and apply the corresponding security update. In the interim, restrict network access to SQL Server (e.g., TCP 1433) to trusted hosts and audit which low-privileged accounts and applications can reach it. Prioritize patching internet-facing, multi-tenant, or shared instances where credentials are broadly distributed.

Affected
Microsoft SQL Server
Estimated exposure
mass≈1M+ SQL Server installations worldwide; a much smaller subset likely reachable by attackers without internal network access — Microsoft SQL Server is one of the most widely deployed enterprise database platforms across on-premises data centers and Azure, but because exploitation requires valid low-privileged credentials, the plausibly exploitable population is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sql server 2017, sql server 2019, sql server 2022, sql server 2025
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.