« Volver al listado

Microsoft

Microsoft SQL Server 2016: vulnerabilidades y CVE

Microsoft SQL Server 2016 tiene 100 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE100
Últimos 12 meses13
Críticas4
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2019-1068Alta (8.8)57%⚠ Explotación activa15 jul 2019
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-47295Alta (8.8)0.99%—14 jul 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55002Alta (8.8)0.91%—14 jul 2026
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-54118Crítica (9.8)1.5%—14 jul 2026
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-54117Crítica (9.8)1.5%—14 jul 2026
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-47296Alta (7.5)0.69%—14 jul 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-40370Alta (8.8)1.0%—12 may 2026
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-33120Alta (8.8)0.91%—14 abr 2026
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-32176Alta (7.8)0.32%—14 abr 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-32167Alta (7.8)0.32%—14 abr 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-26116Alta (8.8)0.99%—10 mar 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26115Alta (8.8)0.96%—10 mar 2026
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-21262Alta (8.8)2.0%—10 mar 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-59499Alta (8.8)1.1%—11 nov 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-55227Alta (8.8)1.4%—9 sept 2025
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-47997Media (5.3)0.84%—9 sept 2025
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2025-53727Alta (8.8)1.2%—12 ago 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-49759Alta (8.8)1.2%—12 ago 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-49758Alta (8.8)0.97%—12 ago 2025
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-24999Alta (8.8)1.7%—12 ago 2025
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-49719Alta (7.5)11%—8 jul 2025
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2024-49043Alta (7.8)0.61%—12 nov 2024
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
CVE-2024-49021Alta (7.8)0.77%—12 nov 2024
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2024-49018Alta (8.8)1.5%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49017Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49016Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49015Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49014Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49013Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49012Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49011Alta (8.8)1.4%—12 nov 2024
SQL Server Native Client Remote Code Execution Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.001 PowerShell1
  2. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft