DIRAS TAKE
Urgent: this vulnerability was added to CISA’s Known Exploited Vulnerabilities list on 2026-08-26 with a federal remediation deadline of 2026-08-29, so prioritize mitigation for internet-facing and critical SQL Server instances immediately.
What is CVE-2019-1068?
An attacker who can access Microsoft SQL Server over the network and has a low-privileged account can trigger remote code execution against the Database Engine; this vulnerability is tracked as CVE-2019-1068. Affected builds include multiple Microsoft SQL Server 2014, 2016, and 2017 Service Pack and Cumulative Update branches listed by the vendor. The flaw requires network access and low privileges (no user interaction) and can allow execution with the SQL Server service account privileges.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft SQL Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR) | unspecified | |
| Microsoft SQL Server 2014.x | 2014 Service Pack 2 for 32-bit Systems (CU) | |
| Microsoft SQL Server 2014.x | 2014 Service Pack 2 for x64-based Systems (CU) | |
| Microsoft SQL Server 2016.x | 2016 for x64-based Systems Service Pack 1 (CU) | |
| Microsoft SQL Server 2017.x | 2017 for x64-based Systems (CU) | |
| Microsoft SQL Server 2016.x | 2016 for x64-based Systems Service Pack 2 (CU) | |
| Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR) | unspecified | |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR) | unspecified | |
| Microsoft SQL Server 2017 for x64-based Systems (GDR) | unspecified | |
| Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR) | unspecified |
Is CVE-2019-1068 being exploited?
CISA added CVE-2019-1068 to the Known Exploited Vulnerabilities catalog on 2026-08-26, and U.S. federal agencies must address it by 2026-08-29. Public exploit code is also available.
How to fix CVE-2019-1068
- Apply vendor guidance and mitigations from Microsoft immediately.
- Restrict network exposure of affected SQL Server instances to trusted networks and management hosts.
- Monitor SQL Server logs and endpoint telemetry for suspicious activity and signs of exploitation.
- Isolate or remove affected instances from production until mitigations are applied or a vendor patch is available.
Frequently asked questions
Is CVE-2019-1068 being actively exploited?
CISA added CVE-2019-1068 to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation deadline of 2026-08-29 for federal agencies, and public exploit code exists.
Which SQL Server versions are affected by CVE-2019-1068?
Microsoft SQL Server 2014, 2016, and 2017 branches are listed as affected in vendor advisories, including Service Pack and Cumulative Update builds noted by the vendor.
Is there a patch for CVE-2019-1068?
A vendor patch is not listed as available in the provided facts; follow Microsoft guidance and applied mitigations until a fixed release is published.
Does CVE-2019-1068 require authentication?
Yes; the vulnerability requires low-privileged credentials (PR:L) but no user interaction, and it is exploitable over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2019-1068
- cve.org/CVERecord?id=CVE-2019-1068
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1068
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026