ZeroHour
Web discovery (articles for new exploits & KEV entries)published ()ingested HazeTec1
Found by web discovery while looking for coverage of CVE-2019-1068

CVE-2019-1068: A remote code execution vulnerability exists in ...

highExploit / PoC exploited in the wildimportance 72CVE-2019-1068
AI summary · glm-5.3-flash

CISA added CVE-2019-1068, a high-severity remote code execution flaw in Microsoft SQL Server, to its KEV catalog after confirming exploitation in the wild.

CVE-2019-1068 (CVSS 8.8, CWE-20) is an improper input validation flaw allowing unauthenticated RCE in Microsoft SQL Server 2014 SP2/SP3, 2016, and 2017 on 32-bit and x64 builds. Exploitation requires low complexity and low privileges with no user interaction, and CISA formally added it to the KEV catalog on August 26, 2026. The CVE was originally published on July 15, 2019 and carries an EPSS score of 52.8%. Administrators must inventory affected SQL Server assets and apply vendor patches on an accelerated timeline.

  • CISA added CVE-2019-1068 to the KEV catalog on August 26, 2026.
  • The flaw enables RCE with low complexity and no user interaction.
  • EPSS score of 52.8% indicates significant exploitation probability.
  • Affected versions span SQL Server 2014 SP2/SP3, 2016, and 2017.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1068
Remote Code Execution in Microsoft SQL Server 2016 and 2017

CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server caused by improper handling of the processing of internal functions (CWE-20, improper input validation). An attacker who can reach SQL Server over the network with low-privileged credentials can trigger the flawed code path and execute arbitrary code, gaining high confidentiality, integrity, and availability impact on the database host. Any organization running affected Microsoft SQL Server versions — including SQL Server 2016 and SQL Server 2017 — is affected. The flaw carries a high EPSS score (52.8% probability of exploitation within 30 days, 99th percentile) and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-26, with headlines reporting it being exploited in active attacks. No public proof-of-concept is known, but the in-the-wild exploitation documented by CISA makes patching urgent; the fix shipped in Microsoft's July 2019 Patch Tuesday security updates.

Do: Apply Microsoft's July 2019 security updates (cumulative updates) for SQL Server 2016 and SQL Server 2017 as directed in the vendor advisory, and inventory all SQL Server instances — especially those reachable on TCP 1433 from the internet — prioritizing exposed or low-privilege-accessible instances. Given the KEV listing, CISA's BOD 26-04 requires patching per vendor instructions (or discontinuing use if mitigation is unavailable) on a prioritized timeline; restrict network access to SQL Server and confirm no unexpected low-privileged accounts or unusual process activity on database hosts as a triage check.

8.853% KEV
  • Microsoft SQL Server
  • microsoft SQL Server 2016
  • microsoft SQL Server 2017
massmillions of SQL Server deployments worldwide, with roughly 1M+ instances exposed on TCP 1433 in public internet scans
Full article179 words · extracted from hazetec.com · click to collapse

Categories

August 26, 2026, Wednesday Vulnerabilities & Exploits

CVE-2019-1068 is a high-severity remote code execution vulnerability (CVSS 8.8) affecting multiple Microsoft SQL Server versions. Caused by improper input validation of internal functions, this flaw is confirmed as exploited in the wild and listed in the CISA KEV catalog. Security teams must prioritize immediate remediation and apply vendor fixes on an accelerated timeline.

Insights

  • The vulnerability is categorized as CWE-20 (Improper Input Validation) and carries an EPSS score of 52.8%, indicating a significant probability of exploitation.
  • While the CVE was published on 15 July 2019, it was formally added to the CISA KEV catalog on 26 August 2026.
  • The flaw impacts a wide range of Microsoft SQL Server versions, including 2014 Service Pack 2 and 3, as well as 2016 and 2017.
  • Attackers can achieve remote code execution with low complexity and low privileges, requiring no user interaction to successfully exploit the system.
  • IT teams must validate all affected 32-bit and x64-based SQL Server assets and apply official vendor patches on an accelerated remediation timeline.

cve-2019-1068 microsoft-sql-server microsoft windows remote-code-execution

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.hazetec.com/briefs/20260826-cve-2019-1068-a-remote-code-execution-vulnerability-exists-in-microsoft-sql.html