Sep 2026: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2026-67383 Published on September 8, 2026

Microsoft SQL Server Information Disclosure Vulnerability
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

Vendor Advisory NVD

Weakness Type

Generation of Error Message Containing Sensitive Information

The software generates an error message that includes sensitive information about its environment, users, or associated data.


Products Associated with CVE-2026-67383

Want to know whenever a new CVE is published for Microsoft Sql Server 2025? stack.watch will email you.

 

Affected Versions

Microsoft SQL Server 2025 (CU8): Microsoft SQL Server 2025 for x64-based Systems (GDR):