Sql Server 2017 Microsoft Sql Server 2017

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Sql Server 2017.

By the Year

In 2026 there have been 54 vulnerabilities in Microsoft Sql Server 2017 with an average score of 7.8 out of ten. Last year, in 2025 Sql Server 2017 had 8 security vulnerabilities published. That is, 46 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.57




Year Vulnerabilities Average Score
2026 54 7.78
2025 8 8.35
2024 81 8.70
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 1 0.00

It may take a day or so for new Sql Server 2017 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Sql Server 2017 Security Vulnerabilities

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77481 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67645 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66819 8.8 - High - September 08, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Sep 2026: Windows OLE DB Information Disclosure Vulnerability
CVE-2026-78441 6.5 - Medium - September 08, 2026

Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Windows OLE DB Remote Code Execution Vulnerability
CVE-2026-78442 8.8 - High - September 08, 2026

Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-69562 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-77488 5.5 - Medium - September 08, 2026

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Integer underflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77486 8.8 - High - September 08, 2026

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

Integer Overflow or Wraparound

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77485 7 - High - September 08, 2026

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77487 8.8 - High - September 08, 2026

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Authorization

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77483 8.8 - High - September 08, 2026

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

1390

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77480 8.8 - High - September 08, 2026

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient Granularity of Access Control

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-73028 8.8 - High - September 08, 2026

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Authorization

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68780 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68779 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68778 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68777 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68776 6.5 - Medium - September 08, 2026

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68775 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67648 6.5 - Medium - September 08, 2026

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67639 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67390 6.5 - Medium - September 08, 2026

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer Over-read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67393 6.5 - Medium - September 08, 2026

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer Over-read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67386 6.5 - Medium - September 08, 2026

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67388 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67381 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67385 8.8 - High - September 08, 2026

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67380 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-66820 8.8 - High - September 08, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66818 8.8 - High - September 08, 2026

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper Privilege Management

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66814 8.8 - High - September 08, 2026

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient Granularity of Access Control

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68786 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67384 8.8 - High - September 08, 2026

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Integer Overflow or Wraparound

Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67376 7.5 - High - September 08, 2026

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Integer Overflow or Wraparound

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68787 7.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68785 4.9 - Medium - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68784 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68781 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67633 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67631 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67630 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67629 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67370 8.8 - High - September 08, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67368 8.8 - High - September 08, 2026

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

insecure temporary file

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77482 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Jul 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-47295 8.8 - High - July 14, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Jul 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-55002 8.8 - High - July 14, 2026

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.

External Control of File Name or Path

Jul 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54118 9.8 - Critical - July 14, 2026

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Marshaling, Unmarshaling

Jul 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-47296 7.5 - High - July 14, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

May 2026: SQL Server Remote Code Execution Vulnerability
CVE-2026-40370 8.8 - High - May 12, 2026

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

External Control of File Name or Path

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2017 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe