Description
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Integer overflow or wraparound in Microsoft SQL Server allows an unauthorized attacker to execute arbitrary code. The flaw arises when the database engine fails to properly validate arithmetic limits, enabling a malicious input to corrupt internal data structures and gain control of execution flow.

Affected Systems

The vulnerability affects Microsoft SQL Server 2017 on its Cumulative Update 31 or the GDR release, and Microsoft SQL Server 2019 on its Cumulative Update 32 or the GDR release. Only the 64‑bit editions are impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability that allows remote code execution. No EPSS score is currently available and the flaw is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based, as the description explicitly states that the attacker can exploit the flaw over a network connection. Successful exploitation would grant the attacker full control over the affected SQL Server instance.

Generated by OpenCVE AI on September 9, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft SQL Server cumulative update or GDR for the affected versions, which patches the integer overflow and wraparound flaw.
  • Ensure that the SQL Server service account runs with the least privilege and restrict database access to only authorized users.
  • Configure network segmentation or firewall rules to block unsolicited inbound traffic aimed at SQL Server ports until the patch is fully applied.

Generated by OpenCVE AI on September 9, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)
Vendors & Products Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
Title Microsoft SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
Weaknesses CWE-122
CWE-190
CPEs cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2017
Microsoft sql Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2017 (gdr) Microsoft Sql Server 2019 (gdr) Sql Server 2017 Sql Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:02.420Z

Reserved: 2026-08-20T20:11:33.672Z

Link: CVE-2026-77486

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:38.466Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:34.277

Modified: 2026-09-15T15:44:38.337

Link: CVE-2026-77486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T23:00:07Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound