• PATCH AVAILABLE

CVE-2026-67643: pre-auth remote code execution in Microsoft Microsoft SQL Server 2022 (CU 26)

An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server 2022 and 2025 instances over a network. CVE-2026-67643 is a heap-based buffer overflow that affects specific 16.x and 17.x builds; affected ranges include 16.0.0.0–before 16.0.4275.2 and 16.0.0–before 16.0.1200.5 for SQL Server 2022, and 17.0.0.0–before 17.0.4085.5 and 17.0.1050.2–before 17.0.1135.8 for SQL Server 2025. An attacker only needs network access to a vulnerable SQL Server instance; no credentials or user interaction are required according to the provided advisory data.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00974
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Treat this as urgent: the flaw allows remote, unauthenticated code execution (no privileges required), so prioritize patching externally reachable SQL Server instances or apply immediate network restrictions until fixed builds are installed.

What is CVE-2026-67643?

An unauthenticated attacker can execute arbitrary code on Microsoft SQL Server 2022 and 2025 instances over a network. CVE-2026-67643 is a heap-based buffer overflow that affects specific 16.x and 17.x builds; affected ranges include 16.0.0.0–before 16.0.4275.2 and 16.0.0–before 16.0.1200.5 for SQL Server 2022, and 17.0.0.0–before 17.0.4085.5 and 17.0.1050.2–before 17.0.1135.8 for SQL Server 2025. An attacker only needs network access to a vulnerable SQL Server instance; no credentials or user interaction are required according to the provided advisory data. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft SQL Server 2022 (CU 26) are affected?

BRANCHAFFECTEDFIXED
Microsoft SQL Server 2022 (CU 26) 16.x16.0.0.0 – before 16.0.4275.216.0.4275.2
Microsoft SQL Server 2022 (GDR) 16.x16.0.0 – before 16.0.1200.516.0.1200.5
Microsoft SQL Server 2025 (CU8) 17.x17.0.0.0 – before 17.0.4085.517.0.4085.5
Microsoft SQL Server 2025 for x64-based Systems (GDR) 17.x17.0.1050.2 – before 17.0.1135.817.0.1135.8

Is CVE-2026-67643 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-67643

  1. Apply the provided updates: install 16.0.4275.2 (CU26) or 16.0.1200.5 (GDR) for SQL Server 2022, or 17.0.4085.5 (CU8) or 17.0.1135.8 (GDR) for SQL Server 2025.
  2. If you cannot patch immediately, restrict network exposure by blocking SQL Server ports at the perimeter and limit access to trusted management networks.
  3. Monitor SQL Server logs and network telemetry for unusual connections or execution activity targeting database services.
  4. Follow Microsoft security guidance and deploy vendor-recommended mitigations and reboot affected hosts after applying updates.

Frequently asked questions

Is CVE-2026-67643 being actively exploited?

There are no public reports of exploitation of CVE-2026-67643 as of 2026-09-30.

Which Microsoft SQL Server versions are affected by CVE-2026-67643?

Affected builds include Microsoft SQL Server 2022 (16.x) from 16.0.0.0 up to but not including 16.0.4275.2 and 16.0.0 up to but not including 16.0.1200.5 (GDR), and Microsoft SQL Server 2025 (17.x) builds from 17.0.0.0 up to but not including 17.0.4085.5 and 17.0.1050.2 up to but not including 17.0.1135.8 (GDR).

Is there a patch for CVE-2026-67643?

Yes. Microsoft provided fixes: 16.0.4275.2 and 16.0.1200.5 for SQL Server 2022, and 17.0.4085.5 and 17.0.1135.8 for SQL Server 2025; install the appropriate build for your branch.

Does CVE-2026-67643 require authentication?

No. The vulnerability permits remote code execution without authentication on affected Microsoft SQL Server builds, according to the advisory details.

References