Junglewise Threat Intelligence

CVE-2026-67630: Microsoft SQL Server out-of-bounds read information disclosure

CVE-2026-67630 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server, a database platform used by many organizations to store and manage critical business data, contains a memory access vulnerability. An authenticated attacker with network access could exploit this flaw to read unauthorized information from the database server's memory, potentially exposing sensitive customer or operational data.

Technical details

This vulnerability is an out-of-bounds read in Microsoft SQL Server that allows an authenticated network attacker to disclose information. The attack requires valid database credentials and network connectivity to the SQL Server instance. By exploiting the memory access flaw, an attacker can read beyond allocated buffer boundaries to access sensitive data in server memory. The vulnerability has a CVSS score of 6.5 (medium severity) and is not currently known to be exploited in the wild. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats