Microsoft
Microsoft SQL Server 2025: vulnerabilidades y CVE
Microsoft SQL Server 2025 tiene 67 vulnerabilidades publicadas, 67 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE67
Últimos 12 meses67
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77488 | Media (5.5) | 0.40% | — | 8 sept 2026 | Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally. |
| CVE-2026-77487 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-77485 | Alta (7) | 0.26% | — | 8 sept 2026 | Use after free in SQL Server allows an authorized attacker to elevate privileges locally. |
| CVE-2026-77484 | Alta (8.8) | 1.7% | — | 8 sept 2026 | Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-77483 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-77481 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-77480 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-73029 | Media (6.5) | 1.00% | — | 8 sept 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-73028 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-68787 | Alta (7.8) | 0.33% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally. |
| CVE-2026-68786 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-68785 | Media (4.9) | 1.1% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-68784 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68781 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68780 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68779 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68778 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68777 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68776 | Media (6.5) | 1.00% | — | 8 sept 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-68775 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-67648 | Media (6.5) | 1.00% | — | 8 sept 2026 | Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67645 | Media (6.5) | 1.00% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67643 | Crítica (9.8) | 0.97% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67642 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-67641 | Media (6.5) | 1.1% | — | 8 sept 2026 | Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. |
| CVE-2026-67639 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-67638 | Alta (8.8) | 0.91% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. |
| CVE-2026-67636 | Crítica (9) | 0.71% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67633 | Media (6.5) | 1.1% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. |
| CVE-2026-67631 | Crítica (9.8) | 0.97% | — | 8 sept 2026 | Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.