CVE-2026-67636 – Microsoft SQL Server Remote Code Execution Vulnerability

CVSS 8.5 IMPORTANT Critical - Same Day Deployment

“A specially crafted database request could turn authorized SQL Server access into remote code execution, putting sensitive data and critical services at risk.”

CVE-2026-67636 is a critical remote code execution vulnerability in Microsoft SQL Server caused by an out-of-bounds read. An authenticated attacker with low privileges could connect to an affected SQL Server over the network and submit a specially crafted query or request that triggers a memory corruption condition. Successful exploitation could allow code execution on the server and result in high confidentiality, integrity, and availability impact. Exploitation requires specific conditions because attack complexity is high, and no user interaction is required.

Key Details

Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-125
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.