Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

A heap‑based buffer overflow in Microsoft SQL Server allows an attacker who has authorized access to execute arbitrary code remotely. The vulnerability is categorized as CWE‑122 and enables code execution on the database server, potentially compromising the confidentiality, integrity, and availability of the data stored within the instance.

Affected Systems

Microsoft SQL Server 2022, specifically the CU 26 release and the GDR (General Distribution Release) version for 64‑bit installations, is affected. The flaw is present only in the x64 build of the product as indicated by the CPE listing.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is unavailable but the lack of KEV listing suggests no widely known public exploit is yet reported. The likely attack vector is a network‑based, authorized attacker – the description indicates that the attacker must have database access privileges. Once exploited, the attacker can run arbitrary code on the host machine, giving full control over the affected server.

Generated by OpenCVE AI on September 9, 2026 at 03:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft SQL Server 2022 cumulative update that contains the fix for CVE-2026-78456 (available via the Microsoft Security Update Guide).
  • Restart the SQL Server service to ensure the updated binaries are loaded.
  • Configure firewall rules or IP restrictions to limit connections to the SQL Server instance to trusted IP ranges during the patch process, and monitor for any anomalous connection attempts.

Generated by OpenCVE AI on September 9, 2026 at 03:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 2)
Vendors & Products Microsoft microsoft Sql Server 2022 (gdr)
Microsoft microsoft Sql Server 2025 (cu 2)

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Title SQL Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sql Server 2022
Weaknesses CWE-122
CPEs cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft sql Server 2022
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Microsoft Sql Server 2022 (gdr) Microsoft Sql Server 2025 (cu 2) Sql Server 2022
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-29T21:46:47.539Z

Reserved: 2026-08-24T16:21:50.287Z

Link: CVE-2026-78456

cve-icon Vulnrichment

Updated: 2026-09-09T09:53:31.939Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:44.280

Modified: 2026-09-15T14:55:45.910

Link: CVE-2026-78456

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:48:43Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow