Junglewise Threat Intelligence

CVE-2026-69562: Microsoft SQL Server out-of-bounds read information disclosure

CVE-2026-69562 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

Microsoft SQL Server contains a vulnerability that allows an attacker to read memory locations outside of intended bounds, potentially exposing sensitive data. An attacker can exploit this remotely without authentication to access confidential information stored in the server's memory, compromising data confidentiality and potentially leading to further attacks.

Technical details

This vulnerability is an out-of-bounds read affecting Microsoft SQL Server. The flaw allows an attacker on the network to craft specific requests that cause the server to access and disclose memory contents beyond the intended data structures. The attack requires network access to SQL Server but does not require authentication. Successful exploitation results in information disclosure, potentially exposing sensitive data such as database contents or server configuration. Microsoft has released security updates to address this vulnerability.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats