Junglewise Threat Intelligence

CVE-2026-67385: Microsoft SQL Server use-after-free remote code execution

CVE-2026-67385 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

Microsoft SQL Server contains a use-after-free vulnerability that allows an authorized database user to execute arbitrary code on the server over the network. An attacker with valid SQL Server credentials can exploit this flaw to gain code execution, potentially compromising the entire database server and any data it contains. This affects organizations that run SQL Server with untrusted or compromised user accounts.

Technical details

The vulnerability is a use-after-free memory safety issue in SQL Server. An authorized attacker with valid database credentials can trigger the flaw over the network to execute arbitrary code with SQL Server process privileges. The vulnerability requires valid authentication (not unauthenticated), but an attacker with even low-privilege database access can escalate to code execution. Microsoft has released security patches to remediate this issue.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats