Microsoft Sql Server 2017
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Sql Server 2017.
By the Year
In 2026 there have been 54 vulnerabilities in Microsoft Sql Server 2017 with an average score of 7.8 out of ten. Last year, in 2025 Sql Server 2017 had 8 security vulnerabilities published. That is, 46 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.57
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 54 | 7.78 |
| 2025 | 8 | 8.35 |
| 2024 | 81 | 8.70 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 0 | 0.00 |
| 2018 | 1 | 0.00 |
It may take a day or so for new Sql Server 2017 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Sql Server 2017 Security Vulnerabilities
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77481
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67645
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66819
8.8 - High
- September 08, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Sep 2026: Windows OLE DB Information Disclosure Vulnerability
CVE-2026-78441
6.5 - Medium
- September 08, 2026
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Windows OLE DB Remote Code Execution Vulnerability
CVE-2026-78442
8.8 - High
- September 08, 2026
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-69562
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-77488
5.5 - Medium
- September 08, 2026
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
Integer underflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77486
8.8 - High
- September 08, 2026
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
Integer Overflow or Wraparound
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77485
7 - High
- September 08, 2026
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77487
8.8 - High
- September 08, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Authorization
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77483
8.8 - High
- September 08, 2026
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
1390
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77480
8.8 - High
- September 08, 2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Insufficient Granularity of Access Control
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-73028
8.8 - High
- September 08, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Authorization
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68780
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68779
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68778
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68777
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68776
6.5 - Medium
- September 08, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of Uninitialized Resource
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68775
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67648
6.5 - Medium
- September 08, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of Uninitialized Resource
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67639
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67390
6.5 - Medium
- September 08, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer Over-read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67393
6.5 - Medium
- September 08, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer Over-read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67386
6.5 - Medium
- September 08, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of Uninitialized Resource
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67388
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67381
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67385
8.8 - High
- September 08, 2026
Use after free in SQL Server allows an authorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67380
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-66820
8.8 - High
- September 08, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66818
8.8 - High
- September 08, 2026
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper Privilege Management
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66814
8.8 - High
- September 08, 2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Insufficient Granularity of Access Control
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68786
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67384
8.8 - High
- September 08, 2026
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
Integer Overflow or Wraparound
Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67376
7.5 - High
- September 08, 2026
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
Integer Overflow or Wraparound
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68787
7.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68785
4.9 - Medium
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68784
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68781
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67633
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67631
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67630
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67629
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67370
8.8 - High
- September 08, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67368
8.8 - High
- September 08, 2026
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
insecure temporary file
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77482
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Heap-based Buffer Overflow
Jul 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-47295
8.8 - High
- July 14, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Jul 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-55002
8.8 - High
- July 14, 2026
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
External Control of File Name or Path
Jul 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54118
9.8 - Critical
- July 14, 2026
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Marshaling, Unmarshaling
Jul 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-47296
7.5 - High
- July 14, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
May 2026: SQL Server Remote Code Execution Vulnerability
CVE-2026-40370
8.8 - High
- May 12, 2026
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
External Control of File Name or Path
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2017 or by Microsoft? Click the Watch button to subscribe.