Sql Server 2025 Microsoft Sql Server 2025

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Sql Server 2025.

By the Year

In 2026 there have been 70 vulnerabilities in Microsoft Sql Server 2025 with an average score of 7.8 out of ten.

Year Vulnerabilities Average Score
2026 70 7.75

It may take a day or so for new Sql Server 2025 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Sql Server 2025 Security Vulnerabilities

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77481 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67645 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67624 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67369 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66819 8.8 - High - September 08, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-77488 5.5 - Medium - September 08, 2026

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Integer underflow

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77485 7 - High - September 08, 2026

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Dangling pointer

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77487 8.8 - High - September 08, 2026

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Authorization

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-77484 8.8 - High - September 08, 2026

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Marshaling, Unmarshaling

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77483 8.8 - High - September 08, 2026

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

1390

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-77480 8.8 - High - September 08, 2026

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient Granularity of Access Control

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-73028 8.8 - High - September 08, 2026

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Authorization

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-47297 8.1 - High - September 08, 2026

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Marshaling, Unmarshaling

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68780 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68779 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68778 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68777 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68776 6.5 - Medium - September 08, 2026

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68775 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67648 6.5 - Medium - September 08, 2026

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67642 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67641 6.5 - Medium - September 08, 2026

Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.

Integer Overflow or Wraparound

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67639 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67638 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67390 6.5 - Medium - September 08, 2026

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer Over-read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67393 6.5 - Medium - September 08, 2026

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer Over-read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67386 6.5 - Medium - September 08, 2026

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

Use of Uninitialized Resource

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67388 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-67381 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67385 8.8 - High - September 08, 2026

Use after free in SQL Server allows an authorized attacker to execute code over a network.

Dangling pointer

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67380 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: SQL Server Elevation of Privilege Vulnerability
CVE-2026-66820 8.8 - High - September 08, 2026

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66818 8.8 - High - September 08, 2026

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper Privilege Management

Sep 2026: Microsoft SQL Server Security Feature Bypass Vulnerability
CVE-2026-66816 6.5 - Medium - September 08, 2026

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Insufficient Logging

Sep 2026: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2026-66814 8.8 - High - September 08, 2026

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Insufficient Granularity of Access Control

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-73029 6.5 - Medium - September 08, 2026

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Buffer Over-read

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68786 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67643 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67636 8.5 - High - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to execute code over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67389 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67384 8.8 - High - September 08, 2026

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

Integer Overflow or Wraparound

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67383 6.5 - Medium - September 08, 2026

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

Generation of Error Message Containing Sensitive Information

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67379 8.5 - High - September 08, 2026

Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Stack Overflow

Sep 2026: Microsoft SQL Server Denial of Service Vulnerability
CVE-2026-67376 7.5 - High - September 08, 2026

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

Integer Overflow or Wraparound

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67378 8.5 - High - September 08, 2026

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Untrusted Pointer Dereference

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68787 7.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-68785 4.9 - Medium - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68784 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-68781 6.5 - Medium - September 08, 2026

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Out-of-bounds Read

Sep 2026: Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-67631 8.8 - High - September 08, 2026

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2025 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe