CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability

criticalknown exploitedpublic exploitCVE-2019-1068
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CSIRTS triage

What
Remote code execution vulnerability allowing execution of arbitrary code in the SQL Server Database Engine service context.
Who is affected
Microsoft SQL Server deployments accessible to remote attackers.
Urgency
Critical; actively exploited and allows unauthenticated or low-privilege remote code execution.
Action
Apply the relevant Microsoft SQL Server security update immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SQL Server

Get an email when a new SQL Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Known Exploited Vulnerabilities (US · database · site)
Severity
critical
Published
2026-08-26
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2019-1068

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2019-1068coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Microsoft SQL Server

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Known Exploited Vulnerabilities