Microsoft Sql Server 2025
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Sql Server 2025.
By the Year
In 2026 there have been 70 vulnerabilities in Microsoft Sql Server 2025 with an average score of 7.8 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 70 | 7.75 |
It may take a day or so for new Sql Server 2025 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Sql Server 2025 Security Vulnerabilities
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77481
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67645
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67624
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67369
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66819
8.8 - High
- September 08, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-77488
5.5 - Medium
- September 08, 2026
Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
Integer underflow
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77485
7 - High
- September 08, 2026
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
Dangling pointer
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77487
8.8 - High
- September 08, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Authorization
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77484
8.8 - High
- September 08, 2026
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Marshaling, Unmarshaling
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77483
8.8 - High
- September 08, 2026
Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
1390
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77480
8.8 - High
- September 08, 2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Insufficient Granularity of Access Control
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-73028
8.8 - High
- September 08, 2026
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Authorization
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-47297
8.1 - High
- September 08, 2026
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Marshaling, Unmarshaling
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68780
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68779
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68778
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68777
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68776
6.5 - Medium
- September 08, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of Uninitialized Resource
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68775
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67648
6.5 - Medium
- September 08, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of Uninitialized Resource
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67642
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67641
6.5 - Medium
- September 08, 2026
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
Integer Overflow or Wraparound
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67639
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67638
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67390
6.5 - Medium
- September 08, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer Over-read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67393
6.5 - Medium
- September 08, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer Over-read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67386
6.5 - Medium
- September 08, 2026
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of Uninitialized Resource
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67388
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67381
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67385
8.8 - High
- September 08, 2026
Use after free in SQL Server allows an authorized attacker to execute code over a network.
Dangling pointer
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67380
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-66820
8.8 - High
- September 08, 2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
SQL Injection
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66818
8.8 - High
- September 08, 2026
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper Privilege Management
Sep 2026: Microsoft SQL Server Security Feature Bypass Vulnerability
CVE-2026-66816
6.5 - Medium
- September 08, 2026
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Insufficient Logging
Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66814
8.8 - High
- September 08, 2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Insufficient Granularity of Access Control
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-73029
6.5 - Medium
- September 08, 2026
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer Over-read
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68786
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67643
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67636
8.5 - High
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67389
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67384
8.8 - High
- September 08, 2026
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
Integer Overflow or Wraparound
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67383
6.5 - Medium
- September 08, 2026
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
Generation of Error Message Containing Sensitive Information
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67379
8.5 - High
- September 08, 2026
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Stack Overflow
Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67376
7.5 - High
- September 08, 2026
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
Integer Overflow or Wraparound
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67378
8.5 - High
- September 08, 2026
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
Untrusted Pointer Dereference
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68787
7.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68785
4.9 - Medium
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68784
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68781
6.5 - Medium
- September 08, 2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds Read
Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67631
8.8 - High
- September 08, 2026
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2025 or by Microsoft? Click the Watch button to subscribe.