Junglewise Threat Intelligence

CVE-2026-67641: Microsoft SQL Server integer overflow in network service

CVE-2026-67641 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server, Microsoft's enterprise database platform, contains an integer overflow vulnerability that allows an authorized user to crash the database service over the network, causing temporary unavailability. An attacker with valid credentials could exploit this to disrupt business operations and customer access to data stored in SQL Server.

Technical details

An integer overflow or wraparound flaw exists in Microsoft SQL Server that can be triggered by an authenticated attacker over the network. The vulnerability allows a user with valid credentials to send specially crafted requests that cause numeric values to overflow, leading to a denial-of-service condition where the SQL Server service crashes or becomes unresponsive. Since authentication is required, an attacker must have valid SQL Server credentials. Microsoft has released security patches to address this vulnerability.

Affected products

  • Microsoft SQL Server <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: NVD published; Microsoft Security Response Center advisory released

References

Related threats