« Back to list

Microsoft

Microsoft SQL Server 2017: vulnerabilities and CVEs

Microsoft SQL Server 2017 has 144 published vulnerabilities, 55 of them in the last 12 months. 5 are rated critical and 1 are listed by CISA as actively exploited.

CVEs144
Last 12 months55
Critical5
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2019-1068High (8.8)57%⚠ Active exploitationJul 15, 2019
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-78442High (8.8)0.82%—Sep 8, 2026
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
CVE-2026-78441Medium (6.5)0.92%—Sep 8, 2026
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
CVE-2026-77488Medium (5.5)0.40%—Sep 8, 2026
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
CVE-2026-77487High (8.8)0.78%—Sep 8, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77486High (8.8)0.82%—Sep 8, 2026
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77485High (7)0.26%—Sep 8, 2026
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-77483High (8.8)0.78%—Sep 8, 2026
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77482High (8.8)0.82%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77481High (8.8)0.91%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-77480High (8.8)0.78%—Sep 8, 2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-73028High (8.8)0.78%—Sep 8, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-68787High (7.8)0.33%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
CVE-2026-68786High (8.8)0.91%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-68785Medium (4.9)1.1%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-68784Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68781Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68780Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68779Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68778Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68777Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68776Medium (6.5)1.00%—Sep 8, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68775High (8.8)0.91%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67648Medium (6.5)1.00%—Sep 8, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67645Medium (6.5)1.00%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67639High (8.8)0.91%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67633Medium (6.5)1.1%—Sep 8, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
CVE-2026-67631Critical (9.8)0.97%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67393Medium (6.5)1.00%—Sep 8, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67390Medium (6.5)1.00%—Sep 8, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67388High (8.8)0.91%—Sep 8, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.001 PowerShell1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft