CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CSIRTS triage
- What
- Remote code execution vulnerability allowing execution of arbitrary code in the SQL Server Database Engine service context.
- Who is affected
- Microsoft SQL Server deployments accessible to remote attackers.
- Urgency
- Critical; actively exploited and allows unauthenticated or low-privilege remote code execution.
- Action
- Apply the relevant Microsoft SQL Server security update immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SQL Server
Get an email when a new SQL Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2019-1068Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2019-1068 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Six Known Exploited Vulnerabilities to Catalogcisa
Recent advisories for Microsoft SQL Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft SQL Server and Power BI: Multiple vulnerabilitiescert-bund · 2026-07-15
- unknownNCSC-2026-0232 [1.00] [M/H] Vulnerabilities fixed in Microsoft SQL Serverncsc-nl · 2026-07-14
- highCVE-2026-54118: Microsoft SQL Server Remote Code Execution Vulnerabilitymsrc · 2026-07-14
- mediumCVE-2026-50468: Microsoft SQL Server Information Disclosure Vulnerabilitymsrc · 2026-07-14
- mediumCVE-2026-54116: Microsoft SQL Server Information Disclosure Vulnerabilitymsrc · 2026-07-14
- highCVE-2026-47295: Microsoft SQL Server Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2015-3246: Red Hat Libuser Race Condition Vulnerability2026-08-26
- criticalCVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability2026-08-26
- criticalCVE-2022-0995: Linux Kernel Out-of-Bounds Write Vulnerability2026-08-26
- criticalCVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds…2026-08-26
- criticalCVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability2026-08-26