Description
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: 1.7% Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A flaw allowing the deserialization of data supplied from untrusted sources in Microsoft SQL Server can be leveraged by an attacker who already has legitimate access rights to perform arbitrary code execution on the database host. This weakness is a classic example of insecure deserialization, identified as CWE‑502. Exploiting it removes any boundaries that normally separate database operations from the operating system, enabling the attacker to gain full control over the underlying server.

Affected Systems

Microsoft SQL Server 2019 (Cumulative Update 32 and GDR), Microsoft SQL Server 2022 (Cumulative Update 26 and GDR), and Microsoft SQL Server 2025 (Cumulative Update 8 and GDR) on x‑64 architectures.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating a high risk of exploitation without advanced prerequisites beyond legitimate credentials. The EPSS score is 1%, yet the lack of listing in the CISA KEV database does not diminish the potential impact. An attacker who can reach the SQL Server instance over the network and possess authorized credentials can trigger the flaw to execute code remotely, potentially compromising the entire host and any connected systems.

Generated by OpenCVE AI on September 9, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update addressing CVE‑2026‑77484 for the affected SQL Server releases as indicated in the Microsoft Security Response Center update guide.
  • If immediate patching is not possible, enforce strict authentication controls, restrict network traffic to the SQL Server, and limit privileged access to the minimum required for legitimate users.
  • Monitor for anomalous database activity and consider implementing network segmentation or firewalls to isolate the SQL Server from untrusted sources until a fix can be applied.

Generated by OpenCVE AI on September 9, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)
Vendors & Products Microsoft microsoft Sql Server 2019 (cu 32)
Microsoft microsoft Sql Server 2019 (gdr)
Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 2)
Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2019
Microsoft sql Server 2022
Microsoft sql Server 2025
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2019 (cu 32) Microsoft Sql Server 2019 (gdr) Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu 2) Microsoft Sql Server 2025 For X64-based Systems (gdr) Sql Server 2019 Sql Server 2022 Sql Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-29T21:46:34.377Z

Reserved: 2026-08-20T20:11:33.672Z

Link: CVE-2026-77484

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:42.766Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:34.023

Modified: 2026-09-15T16:08:26.370

Link: CVE-2026-77484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:49:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data