CVE-2026-77486HighCVSS 8.8

Microsoft SQL Server Remote Code Execution Vulnerability

Published
September 11, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

🎯 Affected products4

  • Microsoft SQL Server 2017 for x64-based Systems (CU 31)
  • Microsoft SQL Server 2017 for x64-based Systems (GDR)
  • Microsoft SQL Server 2019 for x64-based Systems (CU 32)
  • Microsoft SQL Server 2019 for x64-based Systems (GDR)

✅ Remediation

KB5122775 (Security Update) — fixed build 14.0.2130.4 KB5122773 (Security Update) — fixed build 15.0.2190.7 KB5122774 (Security Update) — fixed build 14.0.3550.4 KB5122772 (Security Update) — fixed build 15.0.4490.9

🔗 References (9)