Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A heap-based buffer overflow flaw in Microsoft SQL Server allows an attacker who already has authorized access to the database system to execute arbitrary code over the network. The weakness is a classic out‑of‑bounds write, classified as CWE‑122, and if successfully exploited the attacker can take control of the database engine process, potentially leading to full compromise of the underlying host.

Affected Systems

Affected products are Microsoft SQL Server 2017 in CU 31 and GDR releases, Microsoft SQL Server 2019 in CU 32 and GDR releases, Microsoft SQL Server 2022 in CU 26 and GDR releases, and Microsoft SQL Server 2025 in CU 8 and the GDR build for x64‑based systems. All affected instances are the x64 editions of these products.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. Because the vulnerability is exploitable only by an attacker with existing authorized network access, the attack vector is typically an authenticated session or a trustworthy user account that can query the server. The EPSS score is not available, so current exploitation frequency is unknown, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, a successful exploitation would give the attacker remote code execution on the database server, leaving the system and any connected applications exposed.

Generated by OpenCVE AI on September 9, 2026 at 01:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update or patch released for the affected Microsoft SQL Server version
  • Restrict privileged network access to the SQL Server instance by enforcing strict firewall rules and limiting inbound connections to trusted hosts
  • Enable or enforce network‑level authentication and auditing to detect and prevent unauthorized query activity

Generated by OpenCVE AI on September 9, 2026 at 01:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (cu 31)
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (cu 26)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu8)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (cu 31) Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (cu 26) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu8) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2017 Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:22.423Z

Reserved: 2026-08-20T20:11:33.672Z

Link: CVE-2026-77481

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:15.265Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:33.633

Modified: 2026-09-15T14:55:03.260

Link: CVE-2026-77481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T23:45:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow