Heap-Based Buffer Overflow in SQL Server by Microsoft
CVE-2026-78456
8.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 8 September 2026
What is CVE-2026-78456?
A heap-based buffer overflow vulnerability exists in SQL Server, enabling an authorized attacker to execute arbitrary code remotely through the network. This flaw arises when processing certain data inputs, leading to potential exploitation if not mitigated. It is crucial for users and administrators to apply the latest patches to safeguard their systems against potential attacks that leverage this vulnerability.
Affected Version(s)
Microsoft SQL Server 2022 (CU 26) x64-based Systems 16.0.0.0 < 16.0.4275.2
Microsoft SQL Server 2022 (GDR) x64-based Systems 16.0.0 < 16.0.1200.5