CVE-2026-67378 – Microsoft SQL Server Remote Code Execution Vulnerability
CVSS 8.5
IMPORTANT
Critical - Same Day Deployment
“A specially crafted request could turn authorized SQL Server access into remote code execution, putting sensitive data and critical systems at risk.”
CVE-2026-67378 is a critical remote code execution vulnerability caused by an untrusted pointer dereference in Microsoft SQL Server. An authenticated attacker with low privileges could connect to an affected SQL Server and submit a specially crafted query or request that triggers memory corruption and allows code execution. Successful exploitation requires specific conditions because attack complexity is high, but no user interaction is required.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-822
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.