Technology · Microsoft
Microsoft SQL Server vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 65 vulnerabilities in Microsoft SQL Server: 0 in the last 7 days and 62 in the last 90 days, 8 of them critical and 3 exploited in the wild. The most recent, CVE-2026-78456, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 62
- Critical, all time
- 8
- Exploited in the wild
- 3
Latest Microsoft SQL Server vulnerabilities
- CVE-2026-78456: Microsoft SQL Server heap buffer overflowhighCVSS 8.8EPSS 0.9%
- CVE-2026-77488: Microsoft SQL Server integer underflow vulnerabilitymediumCVSS 5.5EPSS 0.4%
- CVE-2026-77487: Microsoft SQL Server privilege escalation over networkhighCVSS 8.8EPSS 0.8%
- CVE-2026-77486: Microsoft SQL Server integer overflow in network handlerhighCVSS 8.8EPSS 0.8%
- CVE-2026-77485: Microsoft SQL Server use after free privilege escalationhighCVSS 7EPSS 0.3%
- CVE-2026-77484: Microsoft SQL Server unsafe deserialization remote code executionhighCVSS 8.8EPSS 1.7%
- CVE-2026-77483: Microsoft SQL Server weak authentication privilege escalationhighCVSS 8.8EPSS 0.8%
- CVE-2026-77482: Microsoft SQL Server heap-based buffer overflowhighCVSS 8.8EPSS 0.8%
- CVE-2026-77481: Microsoft SQL Server heap-based buffer overflowhighCVSS 8.8EPSS 0.9%
- CVE-2026-77480: Microsoft SQL Server privilege escalation via insufficient access controlhighCVSS 8.8EPSS 0.8%
- CVE-2026-73029: Microsoft SQL Server buffer over-read information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-73028: Microsoft SQL Server privilege escalation via improper access controlhighCVSS 8.8EPSS 0.8%
- CVE-2026-69562: Microsoft SQL Server out-of-bounds read information disclosuremediumCVSS 6.5EPSS 0.9%
- CVE-2026-68787: Microsoft SQL Server heap-based buffer overflowhighCVSS 7.8EPSS 0.3%
- CVE-2026-68786: Microsoft SQL Server heap-based buffer overflowhighCVSS 8.8EPSS 0.9%
- CVE-2026-68785: Microsoft SQL Server heap buffer overflowmediumCVSS 4.9EPSS 1.1%
- CVE-2026-68784: Microsoft SQL Server out-of-bounds read information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-68781: Microsoft SQL Server out-of-bounds read allows information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-68780: Microsoft SQL Server out-of-bounds readmediumCVSS 6.5EPSS 1.0%
- CVE-2026-68779: Microsoft SQL Server out-of-bounds read information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-68777: Microsoft SQL Server out-of-bounds read information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-68776: Microsoft SQL Server uninitialized resource information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-68775: Microsoft SQL Server heap buffer overflowhighCVSS 8.8EPSS 0.9%
- CVE-2026-67648: Microsoft SQL Server uninitialized resource information disclosuremediumCVSS 6.5EPSS 1.0%
- CVE-2026-67645: Microsoft SQL Server out-of-bounds read information disclosuremediumCVSS 6.5EPSS 1.0%
Most severe Microsoft SQL Server vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2012-1856: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2019-1068: Microsoft SQL Server remote code executioncriticalexploited in the wildEPSS 57.9%
- CVE-2026-67643: Microsoft SQL Server heap-based buffer overflowcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-67631: Microsoft SQL Server heap buffer overflowcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-65669: Microsoft SQL Server SQL injection privilege escalationcriticalCVSS 9.6EPSS 0.9%
- CVE-2026-67636: Microsoft SQL Server out-of-bounds read allows remote code executioncriticalCVSS 9EPSS 0.7%
- CVE-2026-67378: Microsoft SQL Server untrusted pointer dereferencecriticalCVSS 9EPSS 0.7%
- CVE-2026-77484: Microsoft SQL Server unsafe deserialization remote code executionhighCVSS 8.8EPSS 1.7%
- CVE-2026-67368: Microsoft SQL Server improper link resolution privilege escalationhighCVSS 8.8EPSS 1.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 1 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 60 | 5 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/sql-server.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Microsoft SQL Server vulnerabilities", https://junglewise.ai/threats/technologies/sql-server, 26 September 2026.