CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks
CISA warns attackers are exploiting CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, to run malicious commands on database servers.
CISA warned that CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, is being exploited in active attacks. Successful exploitation allows an attacker to execute malicious commands on a vulnerable database server, with access limited to the privileges of the SQL Server service account. The warning signals active exploitation of a long-known flaw and makes patching a priority for organizations running affected SQL Server deployments.
- CISA flagged active exploitation of the SQL Server RCE flaw.
- Exploitation grants access at the service account's privilege level.
- Organizations should prioritize patching SQL Server deployments.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1068 | Remote Code Execution in Microsoft SQL Server 2016 and 2017 CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server caused by improper handling of the processing of internal functions (CWE-20, improper input validation). An attacker who can reach SQL Server over the network with low-privileged credentials can trigger the flawed code path and execute arbitrary code, gaining high confidentiality, integrity, and availability impact on the database host. Any organization running affected Microsoft SQL Server versions — including SQL Server 2016 and SQL Server 2017 — is affected. The flaw carries a high EPSS score (52.8% probability of exploitation within 30 days, 99th percentile) and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-26, with headlines reporting it being exploited in active attacks. No public proof-of-concept is known, but the in-the-wild exploitation documented by CISA makes patching urgent; the fix shipped in Microsoft's July 2019 Patch Tuesday security updates. Do: Apply Microsoft's July 2019 security updates (cumulative updates) for SQL Server 2016 and SQL Server 2017 as directed in the vendor advisory, and inventory all SQL Server instances — especially those reachable on TCP 1433 from the internet — prioritizing exposed or low-privilege-accessible instances. Given the KEV listing, CISA's BOD 26-04 requires patching per vendor instructions (or discontinuing use if mitigation is unavailable) on a prioritized timeline; restrict network access to SQL Server and confirm no unexpected low-privileged accounts or unusual process activity on database hosts as a triage check. | 8.8 | 53% | KEV |
| massmillions of SQL Server deployments worldwide, with roughly 1M+ instances exposed on TCP 1433 in public internet scans |
CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server. Successful exploitation could allow an attacker to run malicious commands on a vulnerable database server, with the level of access depending on the privileges assigned to the SQL Server service account.
This source does not provide full text. Read it at cybersecuritynews.com.