Junglewise Threat Intelligence

CVE-2026-67388: Microsoft SQL Server heap overflow allows code execution

CVE-2026-67388 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

Microsoft SQL Server contains a heap-based buffer overflow vulnerability that allows an authorized network attacker to execute arbitrary code on the database server. This could enable an attacker with valid database credentials to compromise the server's integrity, access sensitive data stored in the database, and potentially pivot to other systems on the network.

Technical details

A heap-based buffer overflow exists in Microsoft SQL Server that can be triggered by an authenticated attacker over the network. The vulnerability allows an attacker with valid credentials to overflow a heap buffer and achieve remote code execution with the privileges of the SQL Server service account. The attack requires network access to the SQL Server instance and valid authentication credentials. Successful exploitation grants the attacker the ability to execute arbitrary code on the affected system.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats