Integer Overflow Vulnerability in Microsoft SQL Server
CVE-2026-67641

6.5MEDIUM

What is CVE-2026-67641?

An integer overflow vulnerability in Microsoft SQL Server allows an authorized attacker to exploit the system and cause a denial of service. This flaw can be triggered remotely, impacting the availability of the server and disrupting normal operations. It is essential to address this vulnerability promptly to maintain the integrity and availability of your databases.

Affected Version(s)

Microsoft SQL Server 2022 (CU 26) x64-based Systems 16.0.0.0 < 16.0.4275.2

Microsoft SQL Server 2022 (GDR) x64-based Systems 16.0.0 < 16.0.1200.5

Microsoft SQL Server 2025 (CU8) x64-based Systems 17.0.0.0 < 17.0.4085.5

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.