Microsoft
Microsoft SQL Server 2016: vulnerabilidades y CVE
Microsoft SQL Server 2016 tiene 100 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE100
Últimos 12 meses13
Críticas4
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-1068 | Alta (8.8) | 57% | ⚠ Explotación activa | 15 jul 2019 | A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-47295 | Alta (8.8) | 0.99% | — | 14 jul 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-55002 | Alta (8.8) | 0.91% | — | 14 jul 2026 | External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-54118 | Crítica (9.8) | 1.5% | — | 14 jul 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-54117 | Crítica (9.8) | 1.5% | — | 14 jul 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-47296 | Alta (7.5) | 0.69% | — | 14 jul 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-40370 | Alta (8.8) | 1.0% | — | 12 may 2026 | External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-33120 | Alta (8.8) | 0.91% | — | 14 abr 2026 | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-32176 | Alta (7.8) | 0.32% | — | 14 abr 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32167 | Alta (7.8) | 0.32% | — | 14 abr 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26116 | Alta (8.8) | 0.99% | — | 10 mar 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-26115 | Alta (8.8) | 0.96% | — | 10 mar 2026 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-21262 | Alta (8.8) | 2.0% | — | 10 mar 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-59499 | Alta (8.8) | 1.1% | — | 11 nov 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-55227 | Alta (8.8) | 1.4% | — | 9 sept 2025 | Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-47997 | Media (5.3) | 0.84% | — | 9 sept 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2025-53727 | Alta (8.8) | 1.2% | — | 12 ago 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-49759 | Alta (8.8) | 1.2% | — | 12 ago 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-49758 | Alta (8.8) | 0.97% | — | 12 ago 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-24999 | Alta (8.8) | 1.7% | — | 12 ago 2025 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2025-49719 | Alta (7.5) | 11% | — | 8 jul 2025 | Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. |
| CVE-2024-49043 | Alta (7.8) | 0.61% | — | 12 nov 2024 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability |
| CVE-2024-49021 | Alta (7.8) | 0.77% | — | 12 nov 2024 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2024-49018 | Alta (8.8) | 1.5% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49017 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49016 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49015 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49014 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49013 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49012 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
| CVE-2024-49011 | Alta (8.8) | 1.4% | — | 12 nov 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.