CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[UPDATE] [high] Microsoft SQL Server: Vulnerability enables execution of arbitrary program code with service privileges

high
A remote authenticated attacker can exploit a vulnerability in Microsoft SQL Server 2014, Microsoft SQL Server 2016 and Microsoft SQL Server 2017 to execute arbitrary program code with service privileges.

CSIRTS triage

What
Remote authenticated attacker can execute arbitrary program code with SQL Server service privileges.
Who is affected
Microsoft SQL Server 2014, 2016, and 2017 installations accessible to authenticated users.
Urgency
High; authenticated remote code execution with service-level privileges enables full system compromise.
Action
Apply Microsoft security patches for SQL Server 2014, 2016, and 2017; restrict SQL Server authentication to trusted networks if patches are delayed.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SQL Server

Get an email when a new SQL Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-27
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3035

Recent advisories for Microsoft SQL Server

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories