Junglewise Threat Intelligence

CVE-2026-67376: Microsoft SQL Server integer overflow in network service

CVE-2026-67376 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server, Microsoft's enterprise database platform used by organizations worldwide to store and manage business-critical data, contains an integer overflow vulnerability that can be exploited remotely by attackers. An unauthorized attacker can trigger this flaw over the network to crash the database service, causing service unavailability and disrupting business operations dependent on the database.

Technical details

An integer overflow or wraparound vulnerability exists in Microsoft SQL Server in a network-accessible service component. The vulnerability allows an unauthorized attacker to send specially crafted network packets that trigger an integer overflow condition, leading to a denial of service. The flaw is remotely exploitable over a network without requiring authentication or user interaction. Successful exploitation crashes the SQL Server service, rendering the database unavailable. Microsoft has published security updates to address this issue.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats