Skip to main content

Microsoft security briefs

3323 published alerts for Microsoft products and services.

Microsoft MSRC

CVE-2026-67630

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67630) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67629

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67629) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-67624

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67624) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67393

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67393) was added to Microsoft’s security update guidance. <p>Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67390

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67390) was added to Microsoft’s security update guidance. <p>Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67389

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67389) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67388

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67388) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67386

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67386) was added to Microsoft’s security update guidance. <p>Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67385

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67385) was added to Microsoft’s security update guidance. <p>Use after free in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67384

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67384) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67383

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67383) was added to Microsoft’s security update guidance. <p>Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67381

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-67381) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67380

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67380) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67379

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67379) was added to Microsoft’s security update guidance. <p>Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67378

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67378) was added to Microsoft’s security update guidance. <p>Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67376

Microsoft SQL Server Denial of Service vulnerability

Microsoft SQL Server Denial of Service vulnerability (CVE-2026-67376) was added to Microsoft’s security update guidance. <p>Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67373

Microsoft SQL Server Remote Code Execution vulnerability

Microsoft SQL Server Remote Code Execution vulnerability (CVE-2026-67373) was added to Microsoft’s security update guidance. <p>Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67370

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-67370) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67369

Microsoft SQL Server Information Disclosure vulnerability

Microsoft SQL Server Information Disclosure vulnerability (CVE-2026-67369) was added to Microsoft’s security update guidance. <p>Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-67368

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-67368) was added to Microsoft’s security update guidance. <p>Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66820

SQL Server Elevation of Privilege vulnerability

SQL Server Elevation of Privilege vulnerability (CVE-2026-66820) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-66819

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66819) was added to Microsoft’s security update guidance. <p>Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66818

Microsoft SQL Server Elevation of Privilege vulnerability

Microsoft SQL Server Elevation of Privilege vulnerability (CVE-2026-66818) was added to Microsoft’s security update guidance. <p>Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-66816

Microsoft SQL Server Security Feature Bypass vulnerability

Microsoft SQL Server Security Feature Bypass vulnerability (CVE-2026-66816) was added to Microsoft’s security update guidance. <p>Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.</p> If you need help checking exposure, call (864) 335-9223.