CVE-2026-67643
published 2026-09-08CVE-2026-67643: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.83%
55.5th percentile
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sql_server_2022 | >= 16.0.0 < 16.0.1200.5 | 16.0.1200.5 |
| microsoft | microsoft_sql_server_2022 | >= 16.0.0.0 < 16.0.4275.2 | 16.0.4275.2 |
| microsoft | microsoft_sql_server_2025 | >= 17.0.0.0 < 17.0.4085.5 | 17.0.4085.5 |
| microsoft | microsoft_sql_server_2025_for_x64-based_systems | >= 17.0.1050.2 < 17.0.1135.8 | 17.0.1135.8 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Sans Isc
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
blogs_sans_isc·2026-09-08·CVSS 7.8
CVE-2026-81963 [HIGH] September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
September 2026 Microsoft Patch Tuesday
Published: 2026-09-08. Last Updated: 2026-09-08 19:20:30 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
A few vulnerabilities worth mentioning:
Windows Update Stack Elevation of Privilege Vulnerability (CVE-2026-81963)
Microsoft reports that CVE-2026-81963 is being exploited, though it was not publicly disclosed b
Rapid7
Patch Tuesday - September 2026
blogs_rapid7·2026-09-08·CVSS 7.8
CVE-2026-85880 [HIGH] Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today.
## Windows ALPC: zero-day EoP
The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the batt
Talos
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-09-08·CVSS 8.8
CVE-2026-81963 [HIGH] Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Microsoft notes that 2 of the vulnerabilities disclosed this month have been exploited in the wild:
CVE-2026-81963 affects Windows Update Stack. CVE-2026-81963 is a elevation of privilege vulnerability associated with Improper Link Resolution Before File Access ('Link Following') and Improper Access Control and has a CVSS base score of 7.8.
CVE-2026-85880 affects Windows Advanced Local Procedure Call (ALPC). CVE-2026-85880 is a elevation of privilege vulnerability associated with Heap-based Buffer Overflow and Us
Qualys
Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
blogs_qualys·2026-09-08
CVE-2026-75650 Microsoft and Adobe Patch Tuesday, September 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for September2026
Adobe Patch for September 2026
Zero-day Vulnerabilities Patched inSeptemberPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inSeptemberPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security updates are packed with security fixes, providing organizations with important updates to help protect their environments from emerging threats.
This Patch Tuesday is Microsoft’s largest security update ever, marking a significant increase over other recent massive releases, including the 570 security fla
Crowdstrike
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
blogs_crowdstrike
CVE-2026-81963 September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs Sep 08, 2026
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks Sep 02, 2026
CrowdStrike Announces Agentic Identity Provider Sep 02, 2026
CrowdStrike Delivers the Next Evolution of the Agentic SOC Sep 02, 2026
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs Sep 08, 2026
CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks Sep 02, 2026
CrowdStrike Announces Agentic Identity Provider Sep 02, 2026
CrowdStrike Delivers the Next Evolution of the Agentic SOC Sep 02, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Under
2026-09-08
Published