Junglewise Threat Intelligence

CVE-2026-67378: Microsoft SQL Server untrusted pointer dereference

CVE-2026-67378 · Severity: critical · CVSS 9 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

Microsoft SQL Server contains a pointer dereference vulnerability that allows an unauthenticated attacker to execute arbitrary code remotely. This could lead to complete compromise of the database system, including unauthorized access to sensitive customer data, service disruption, and potential lateral movement within a corporate network.

Technical details

The vulnerability involves an untrusted pointer dereference in SQL Server that enables remote code execution. The flaw can be exploited over the network without requiring prior authentication, allowing an attacker to execute arbitrary code with the privileges of the SQL Server process. This is a memory corruption issue that could be triggered through specially crafted network requests. Microsoft has released a security update to address this issue.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats