Microsoft Sql Server 2025 vulnerabilities
69 known vulnerabilities affecting microsoft/microsoft_sql_server_2025.
Total CVEs
69
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH41MEDIUM26
Vulnerabilities
Page 3 of 4
CVE-2026-68787P3HIGHCVSS 7.8≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68787 [HIGH] CWE-122 CVE-2026-68787: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
nvd
CVE-2026-67376P3HIGHCVSS 7.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67376 [HIGH] CWE-190 CVE-2026-67376: Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-67390P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67390 [MEDIUM] CWE-126 CVE-2026-67390: Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-73029P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-73029 [MEDIUM] CWE-126 CVE-2026-73029: Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67393P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67393 [MEDIUM] CWE-126 CVE-2026-67393: Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-66816P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-66816 [MEDIUM] CWE-778 CVE-2026-66816: Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2026-50468P3MEDIUMCVSS 6.5≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-50468 [MEDIUM] CWE-126 CVE-2026-50468: Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67386P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67386 [MEDIUM] CWE-908 CVE-2026-67386: Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information ov
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68776P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68776 [MEDIUM] CWE-908 CVE-2026-68776: Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information ov
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67648P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67648 [MEDIUM] CWE-908 CVE-2026-67648: Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information ov
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-54116P3MEDIUMCVSS 6.5≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-54116 [MEDIUM] CWE-843 CVE-2026-54116: Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized att
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68777P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68777 [MEDIUM] CWE-125 CVE-2026-68777: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68778P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68778 [MEDIUM] CWE-125 CVE-2026-68778: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68780P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68780 [MEDIUM] CWE-125 CVE-2026-68780: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67369P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67369 [MEDIUM] CWE-125 CVE-2026-67369: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67389P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67389 [MEDIUM] CWE-125 CVE-2026-67389: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67629P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67629 [MEDIUM] CWE-125 CVE-2026-67629: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68784P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68784 [MEDIUM] CWE-125 CVE-2026-68784: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68781P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68781 [MEDIUM] CWE-125 CVE-2026-68781: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67630P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67630 [MEDIUM] CWE-125 CVE-2026-67630: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd