Junglewise Threat Intelligence

CVE-2026-77482: Microsoft SQL Server heap-based buffer overflow

CVE-2026-77482 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft SQL Server contains a heap-based buffer overflow vulnerability that allows an attacker with network access to execute arbitrary code on the affected system. This could lead to complete system compromise, data theft, and service disruption for organizations relying on SQL Server for critical database operations.

Technical details

A heap-based buffer overflow exists in Microsoft SQL Server that can be triggered remotely without requiring authentication. The vulnerability stems from insufficient bounds checking in memory handling, allowing an attacker to overflow a heap buffer and overwrite adjacent memory structures. By crafting a malicious network request, an attacker can achieve remote code execution with the privileges of the SQL Server process. The attack requires only network connectivity to the SQL Server instance and no prior user interaction or credentials.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats