Junglewise Threat Intelligence

CVE-2026-68779: Microsoft SQL Server out-of-bounds read information disclosure

CVE-2026-68779 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server is Microsoft's enterprise database platform used to store and manage business-critical data. An authorized database user can trigger an out-of-bounds memory read that exposes sensitive information, potentially leaking database contents or system memory across the network. This could compromise confidential customer or business data stored in the database.

Technical details

This vulnerability is an out-of-bounds read in Microsoft SQL Server that allows an authenticated attacker to read memory outside the bounds of allocated buffers. The attack requires valid database credentials and network access to the SQL Server instance. By exploiting this memory read vulnerability, an attacker can extract sensitive information from the SQL Server process memory and transmit it over the network. The exact vulnerable component and root cause are not detailed in the reference material provided.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats