Microsoft Sql Server 2025 vulnerabilities
69 known vulnerabilities affecting microsoft/microsoft_sql_server_2025.
Total CVEs
69
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH41MEDIUM26
Vulnerabilities
Page 4 of 4
CVE-2026-67641P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67641 [MEDIUM] CWE-190 CVE-2026-67641: Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a ne
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
nvd
CVE-2026-67624P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67624 [MEDIUM] CWE-125 CVE-2026-67624: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-68779P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68779 [MEDIUM] CWE-125 CVE-2026-68779: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67645P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67645 [MEDIUM] CWE-125 CVE-2026-67645: Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a networ
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-77485P3HIGHCVSS 7.0≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-77485 [HIGH] CWE-416 CVE-2026-77485: Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-67383P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67383 [MEDIUM] CWE-209 CVE-2026-67383: Generation of error message containing sensitive information in SQL Server allows an authorized atta
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-67633P3MEDIUMCVSS 6.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-67633 [MEDIUM] CWE-125 CVE-2026-67633: Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
nvd
CVE-2026-68785P3MEDIUMCVSS 4.9≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-68785 [MEDIUM] CWE-122 CVE-2026-68785: Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a networ
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-77488P4MEDIUMCVSS 5.5≥ 17.0.0.0, < 17.0.4085.52026-09-08
CVE-2026-77488 [MEDIUM] CWE-191 CVE-2026-77488: Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose infor
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
nvd
← Previous4 / 4