Microsoft SQL Server
64 known vulnerabilities in Microsoft SQL Server, 4 critical, 2 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2020-0618 CVSS 8.8 high · actively exploited Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
- CVE-2019-1068 CVSS 8.8 high · actively exploited Microsoft SQL Server Remote Code Execution Vulnerability
Latest vulnerabilities
- CVE-2026-78456 CVSS 8.8 high Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-78442 CVSS 8.8 high Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-78441 CVSS 6.5 medium Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
- CVE-2026-77488 CVSS 5.5 medium Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
- CVE-2026-77487 CVSS 8.8 high Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-77486 CVSS 8.8 high Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-77485 CVSS 7.0 high Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-77484 CVSS 8.8 high Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-77483 CVSS 8.8 high Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-77482 CVSS 8.8 high Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-77481 CVSS 8.8 high Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-77480 CVSS 8.8 high Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-73029 CVSS 6.5 medium Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-73028 CVSS 8.8 high Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69562 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
- CVE-2026-68787 CVSS 7.8 high Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
- CVE-2026-68786 CVSS 8.8 high Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-68785 CVSS 4.9 medium Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-68784 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68781 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68780 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68779 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68778 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68777 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68776 CVSS 6.5 medium Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-68775 CVSS 8.8 high Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- CVE-2026-67648 CVSS 6.5 medium Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-67645 CVSS 6.5 medium Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-67643 CVSS 9.8 critical Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-67642 CVSS 8.8 high Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.