Microsoft
Microsoft SQL Server 2017: vulnerabilities and CVEs
Microsoft SQL Server 2017 has 144 published vulnerabilities, 55 of them in the last 12 months. 5 are rated critical and 1 are listed by CISA as actively exploited.
CVEs144
Last 12 months55
Critical5
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1068 | High (8.8) | 57% | ⚠ Active exploitation | Jul 15, 2019 | A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78442 | High (8.8) | 0.82% | — | Sep 8, 2026 | Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. |
| CVE-2026-78441 | Medium (6.5) | 0.92% | — | Sep 8, 2026 | Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-77488 | Medium (5.5) | 0.40% | — | Sep 8, 2026 | Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally. |
| CVE-2026-77487 | High (8.8) | 0.78% | — | Sep 8, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-77486 | High (8.8) | 0.82% | — | Sep 8, 2026 | Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-77485 | High (7) | 0.26% | — | Sep 8, 2026 | Use after free in SQL Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-77483 | High (8.8) | 0.78% | — | Sep 8, 2026 | Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-77482 | High (8.8) | 0.82% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-77481 | High (8.8) | 0.91% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-77480 | High (8.8) | 0.78% | — | Sep 8, 2026 | Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-73028 | High (8.8) | 0.78% | — | Sep 8, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-68787 | High (7.8) | 0.33% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally. |
| CVE-2026-68786 | High (8.8) | 0.91% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-68785 | Medium (4.9) | 1.1% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-68784 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68781 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68780 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68779 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68778 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68777 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68776 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68775 | High (8.8) | 0.91% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-67648 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67645 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67639 | High (8.8) | 0.91% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-67633 | Medium (6.5) | 1.1% | — | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. |
| CVE-2026-67631 | Critical (9.8) | 0.97% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67393 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67390 | Medium (6.5) | 1.00% | — | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67388 | High (8.8) | 0.91% | — | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.