Out-of-bounds read in Microsoft SQL Server - CVE-2026-67636

 

Out-of-bounds read in Microsoft SQL Server - CVE-2026-67636

Published: September 9, 2026


Vulnerability identifier: #VU148389
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67636
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds read in SQL Server when processing a specially crafted query or request. A remote user can submit a specially crafted query or request to execute arbitrary code.

Exploitation requires specific protocol settings or configurations, and user interaction is not required.


Affected software

Microsoft SQL Server

How to mitigate CVE-2026-67636

Install security update from vendor's website.

Microsoft SQL Server - addressed in versions 15.0.2190.7, 15.0.4490.9, 16.0.1200.5, 16.0.4275.2, 17.0.1135.8, 17.0.4085.5

External References

Related Security Bulletins