Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local code execution
Action: Patch
AI Analysis

Impact

The vulnerability is a heap‑based buffer overflow in Microsoft SQL Server that allows an authorized attacker to execute arbitrary code locally. The flaw arises when malformed data is processed by the query engine, leading to corrupted heap memory. Because the buffer overrun can cause arbitrary code execution, the compromise grants the attacker the privileges of the SQL Server service account.

Affected Systems

Affected are Microsoft SQL Server 2017, 2019, 2022, and 2025 on x64 systems. Specific vulnerable releases include the cumulative update (CU) 31 for 2017, CU 32 for 2019, CU 26 for 2022, and CU 8 for 2025, as well as the corresponding any exposure fixes (GDR) for each version. These apply to 64‑bit editions of the database engine.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability. EPSS is not available, and the issue is not yet listed in CISA’s KEV catalog. Because the vulnerability requires an authorized attacker, the likely attack vector is a privileged user or a compromised account that can submit specially crafted requests to the SQL Server service. Once exploited, the attacker gains code execution with the SQL Server service account privileges. The absence of publicly known exploits and lack of KEV listing suggest that exploitation is not widely automated yet, but the high severity warrants immediate patching.

Generated by OpenCVE AI on September 10, 2026 at 02:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE-2026-68787 to all affected SQL Server instances.
  • Limit SQL Server logins to the minimum privileges required for each application, ensuring that no unnecessary privileged accounts can submit malicious queries.
  • Use network segmentation or firewall rules to restrict access to the SQL Server instances to only trusted hosts or administrators.

Generated by OpenCVE AI on September 10, 2026 at 02:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Thu, 10 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (cu 26) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu8) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:40.774Z

Reserved: 2026-07-31T16:33:08.215Z

Link: CVE-2026-68787

cve-icon Vulnrichment

Updated: 2026-09-09T10:04:39.606Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:26.313

Modified: 2026-09-15T20:00:14.277

Link: CVE-2026-68787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T23:45:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow