• PATCH AVAILABLE

CVE-2026-67378: pre-auth remote code execution in Microsoft Microsoft SQL Server 2019 (CU 32)

An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server instances by exploiting an untrusted pointer dereference vulnerability (CVE-2026-67378). Affected builds include Microsoft SQL Server 2019, 2022, and 2025 releases listed as earlier than the fixed builds (for example 15.0.4490.9, 16.0.4275.2, 17.0.4085.5); see vendor advisories for full affected-build ranges. The flaw can be triggered remotely over the network without valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9CRITICAL
EPSS
0.00707
CWE
CWE-822
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: treat this as high priority because the vulnerability allows unauthenticated remote code execution over the network; apply the vendor fixes or block access to SQL Server instances until patched.

What is CVE-2026-67378?

An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server instances by exploiting an untrusted pointer dereference vulnerability (CVE-2026-67378). Affected builds include Microsoft SQL Server 2019, 2022, and 2025 releases listed as earlier than the fixed builds (for example 15.0.4490.9, 16.0.4275.2, 17.0.4085.5); see vendor advisories for full affected-build ranges. The flaw can be triggered remotely over the network without valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Microsoft Microsoft SQL Server 2019 (CU 32) are affected?

BRANCHAFFECTEDFIXED
Microsoft SQL Server 2019 (CU 32) 15.x15.0.0.0 – before 15.0.4490.915.0.4490.9
Microsoft SQL Server 2019 (GDR) 15.x15.0.0 – before 15.0.2190.715.0.2190.7
Microsoft SQL Server 2022 (CU 26) 16.x16.0.0.0 – before 16.0.4275.216.0.4275.2
Microsoft SQL Server 2022 (GDR) 16.x16.0.0 – before 16.0.1200.516.0.1200.5
Microsoft SQL Server 2025 (CU8) 17.x17.0.0.0 – before 17.0.4085.517.0.4085.5
Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x17.0.1050.2 – before 17.0.1135.817.0.1135.8

Is CVE-2026-67378 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-67378

  1. Apply Microsoft’s updates that contain the fixes (install builds 15.0.4490.9, 15.0.2190.7, 16.0.4275.2, 16.0.1200.5, 17.0.4085.5 or 17.0.1135.8 as appropriate).
  2. If you cannot patch immediately, restrict network exposure of SQL Server instances to trusted hosts and networks and block or filter SQL Server traffic at the perimeter.
  3. Monitor SQL Server logs and network traffic for suspicious activity and unauthorized connections related to database services.
  4. Follow Microsoft’s guidance and update inventories to ensure affected builds are identified and remediated.

Frequently asked questions

Is CVE-2026-67378 being actively exploited?

There are no public reports of exploitation and it is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-30.

Which Microsoft SQL Server versions are affected by CVE-2026-67378?

Microsoft SQL Server 2019, 2022 and 2025 builds are affected where the installed build is earlier than the fixed builds noted by Microsoft (see fixed builds such as 15.0.4490.9, 16.0.4275.2 and 17.0.4085.5).

Is there a patch for CVE-2026-67378?

Yes, Microsoft has issued fixes; install the specified fixed builds for your SQL Server branch as provided in the vendor advisories.

Does CVE-2026-67378 require authentication?

No, the vulnerability can be exploited without authentication against affected Microsoft SQL Server builds; it can be triggered remotely over the network.

References