Junglewise Threat Intelligence

CVE-2026-67639: Microsoft SQL Server heap-based buffer overflow

CVE-2026-67639 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server is a widely-used database platform that manages sensitive corporate data and business-critical applications. A heap-based buffer overflow vulnerability allows an authorized attacker to execute arbitrary code on the database server, potentially leading to data theft, corruption, or service disruption.

Technical details

A heap-based buffer overflow exists in SQL Server that can be exploited by an authenticated attacker to execute arbitrary code remotely over the network. The vulnerability stems from improper memory allocation and bounds checking in a specific SQL Server component. An attacker with valid database credentials and network access to the SQL Server can craft a malicious query or command to overflow a heap buffer, achieving remote code execution with the privileges of the SQL Server service. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats