Junglewise Threat Intelligence

CVE-2026-67638: Microsoft SQL Server heap-based buffer overflow in network component

CVE-2026-67638 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

Microsoft SQL Server contains a heap-based buffer overflow vulnerability that allows an authorized network user to execute arbitrary code on the affected database server. This vulnerability can lead to complete compromise of the SQL Server instance, potentially exposing sensitive customer data and disrupting critical business operations that depend on the database.

Technical details

A heap-based buffer overflow exists in Microsoft SQL Server that can be triggered by an authorized attacker over the network. The vulnerability allows remote code execution (RCE) with the privileges of the SQL Server process. An attacker must first authenticate to the SQL Server instance before exploiting the flaw. Successful exploitation results in arbitrary code execution, enabling full system compromise. A patch is expected to be available through Microsoft's security update process.

Affected products

  • Microsoft SQL Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats