DIRAS TAKE
Urgent: this flaw can be exploited without authentication, so prioritize installing the vendor fixes for your branch or immediately restrict SQL Server network exposure until you can update.
What is CVE-2026-67636?
An unauthenticated attacker can trigger a memory out-of-bounds read in Microsoft SQL Server and potentially execute code over a network. CVE-2026-67636 affects multiple SQL Server branches: 2019 (CU32) 15.x before 15.0.4490.9, 2019 (GDR) 15.x before 15.0.2190.7, 2022 (CU26) 16.x before 16.0.4275.2, 2022 (GDR) 16.x before 16.0.1200.5, 2025 (CU8) 17.x before 17.0.4085.5, and 2025 (GDR) 17.x 17.0.1050.2–before 17.0.1135.8; fixed builds are listed by the vendor. Exploitation requires network access but no valid credentials or user interaction.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Microsoft Microsoft SQL Server 2019 (CU 32) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft SQL Server 2019 (CU 32) 15.x | 15.0.0.0 – before 15.0.4490.9 | 15.0.4490.9 |
| Microsoft SQL Server 2019 (GDR) 15.x | 15.0.0 – before 15.0.2190.7 | 15.0.2190.7 |
| Microsoft SQL Server 2022 (CU 26) 16.x | 16.0.0.0 – before 16.0.4275.2 | 16.0.4275.2 |
| Microsoft SQL Server 2022 (GDR) 16.x | 16.0.0 – before 16.0.1200.5 | 16.0.1200.5 |
| Microsoft SQL Server 2025 (CU8) 17.x | 17.0.0.0 – before 17.0.4085.5 | 17.0.4085.5 |
| Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x | 17.0.1050.2 – before 17.0.1135.8 | 17.0.1135.8 |
Is CVE-2026-67636 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-30.
How to fix CVE-2026-67636
- Apply the vendor updates that contain the fixes: 15.0.4490.9 or 15.0.2190.7 for SQL Server 2019 branches, 16.0.4275.2 or 16.0.1200.5 for SQL Server 2022 branches, and 17.0.4085.5 or 17.0.1135.8 for SQL Server 2025 branches.
- If you cannot patch immediately, restrict access to SQL Server instances from untrusted networks and block unnecessary ports at the network perimeter.
- Monitor SQL Server logs and network traffic for suspicious queries or unexpected connections and apply vendor guidance for intrusion detection.
Frequently asked questions
Is CVE-2026-67636 being actively exploited?
There are no public reports of active exploitation and CISA has not listed this CVE as of 2026-09-30.
Which Microsoft SQL Server versions are affected by CVE-2026-67636?
Affected branches include Microsoft SQL Server 2019 (CU32 and GDR), 2022 (CU26 and GDR), and 2025 (CU8 and GDR) with specific build ranges listed in the vendor advisory.
Is there a patch for CVE-2026-67636?
Yes. Fixed builds are 15.0.4490.9 and 15.0.2190.7 for SQL Server 2019 branches, 16.0.4275.2 and 16.0.1200.5 for 2022 branches, and 17.0.4085.5 and 17.0.1135.8 for 2025 branches.
Does CVE-2026-67636 require authentication?
No. The vulnerability can be exploited without valid credentials, requiring only network access to the vulnerable SQL Server instance.
References
- nvd.nist.gov/vuln/detail/CVE-2026-67636
- cve.org/CVERecord?id=CVE-2026-67636
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67636
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026