CVE-2026-77486
massInteger Overflow RCE in Microsoft SQL Server
CVE-2026-77486 is an integer overflow/wraparound flaw (CWE-190) in Microsoft SQL Server that leads to memory corruption (heap-based buffer overflow, CWE-122) when the database engine processes crafted input. An unauthorized (unauthenticated) attacker can trigger it remotely over the network, though the CVSS vector (UI:R) indicates some form of user interaction is required for successful exploitation. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, so an attacker could run arbitrary code in the context of the SQL Server process. Any organization running a affected supported release of Microsoft SQL Server is potentially exposed; the source data does not specify which version branches are affected, so defenders must consult Microsoft's advisory for exact version ranges. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns a 0.6% probability of exploitation within 30 days (roughly the 45th percentile).
What to do: Identify all SQL Server instances in your environment and apply Microsoft's security update for CVE-2026-77486, checking Microsoft's advisory for the exact affected version ranges and update packages since they are not enumerated here. In the interim, restrict exposure of SQL Server (e.g., TCP 1433) to trusted networks only, and because user interaction is part of the attack path, caution users against opening untrusted files, links, or query content that could drive interaction with the server. Monitor Microsoft and CISA channels for updates, as post-disclosure additions to KEV or new PoCs would raise urgency.
| Microsoft SQL Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sql server 2017, sql server 2019
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.