Description
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

A heap‑based buffer overflow in Microsoft SQL Server enables an attacker with authorized network access to execute arbitrary code. The vulnerability is triggered by a crafted packet sent over the network to an SQL Server instance, allowing the attacker to take control of the executing process.

Affected Systems

Microsoft SQL Server 2017 (CU 31 and GDR), Microsoft SQL Server 2019 (CU 32 and GDR), Microsoft SQL Server 2022 (CU 26 and GDR), and Microsoft SQL Server 2025 (CU 8 and GDR). All affected versions run on 64‑bit x64 systems.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. While the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. However, the attack requires network connectivity to a vulnerable SQL Server instance and authorized user credentials, meaning it is likely exploitable by a threat actor with legitimate access to the database network.

Generated by OpenCVE AI on September 8, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update or Security Bulletin for the affected SQL Server versions, as published on the Microsoft Security Response Center.
  • Restrict access to the SQL Server instances by configuring firewalls or network segmentation so that only trusted internal hosts can reach the database servers.
  • Ensure that only essential accounts with the minimum required privileges are allowed to connect to the SQL Server, and block all unnecessary network traffic to the database ports.

Generated by OpenCVE AI on September 8, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (cu 26) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu8) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:37.897Z

Reserved: 2026-07-29T22:49:19.796Z

Link: CVE-2026-67631

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:43.816Z

cve-icon NVD

Status : Modified

Published: 2026-09-08T18:18:23.590

Modified: 2026-09-17T20:17:00.313

Link: CVE-2026-67631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T18:15:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow