DIRAS TAKE
Treat this as urgent: the flaw permits remote code execution without authentication, so prioritize applying the vendor updates that contain the listed fixes or otherwise restrict network exposure to SQL Server immediately.
What is CVE-2026-67631?
An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server instances by exploiting a heap-based buffer overflow (CVE-2026-67631). The flaw affects multiple SQL Server branches: 2017, 2019, 2022 and 2025 builds before the fixed updates listed by the vendor (see fixed builds). Exploitation requires network access to the SQL Server service but does not require valid credentials or user interaction. The vulnerability is rated critical and allows full system compromise if exploited. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Microsoft SQL Server 2017 (CU 31) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft SQL Server 2017 (CU 31) 14.x | 14.0.0 – before 14.0.3550.4 | 14.0.3550.4 |
| Microsoft SQL Server 2017 (GDR) 14.x | 14.0.0 – before 14.0.2130.4 | 14.0.2130.4 |
| Microsoft SQL Server 2019 (CU 32) 15.x | 15.0.0.0 – before 15.0.4490.9 | 15.0.4490.9 |
| Microsoft SQL Server 2019 (GDR) 15.x | 15.0.0 – before 15.0.2190.7 | 15.0.2190.7 |
| Microsoft SQL Server 2022 (CU 26) 16.x | 16.0.0.0 – before 16.0.4275.2 | 16.0.4275.2 |
| Microsoft SQL Server 2022 (GDR) 16.x | 16.0.0 – before 16.0.1200.5 | 16.0.1200.5 |
| Microsoft SQL Server 2025 (CU8) 17.x | 17.0.0.0 – before 17.0.4085.5 | 17.0.4085.5 |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x | 17.0.1050.2 – before 17.0.1135.8 | 17.0.1135.8 |
Is CVE-2026-67631 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-67631
- Apply the vendor updates that include the fixes (for example 14.0.3550.4, 14.0.2130.4, 15.0.4490.9, 15.0.2190.7, 16.0.4275.2, 16.0.1200.5, 17.0.4085.5, 17.0.1135.8).
- If you cannot immediately patch, restrict access to SQL Server ports to trusted hosts and networks and block internet exposure.
- Monitor SQL Server logs and network traffic for suspicious connections and unexpected processes spawned by sqlservr.exe.
- Follow Microsoft’s guidance for installing the updates and rebooting affected systems where required.
Frequently asked questions
Is CVE-2026-67631 being actively exploited?
There are no public reports of exploitation as of 2026-09-30.
Which Microsoft SQL Server versions are affected by CVE-2026-67631?
Multiple branches are affected: Microsoft SQL Server 2017, 2019, 2022 and 2025 builds prior to the fixed builds listed by Microsoft (see fixed versions such as 14.0.3550.4, 15.0.4490.9, 16.0.4275.2, 17.0.4085.5).
Is there a patch for CVE-2026-67631?
Yes. Microsoft published fixes; update to the fixed builds named by Microsoft for your SQL Server branch (examples listed above).
Does CVE-2026-67631 require authentication?
No. The vulnerability can be exploited without authentication; an attacker needs only network access to the SQL Server service.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67631
- cve.org/CVERecord?id=CVE-2026-67631
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67631
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026