CVE-2026-67383HighCVSS 6.5
Microsoft SQL Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
🎯 Affected products2
- Microsoft SQL Server 2025 for x64-based Systems (CU8)
- Microsoft SQL Server 2025 for x64-based Systems (GDR)
✅ Remediation
KB5122770 (Security Update) — fixed build 17.0.1135.8 KB5122769 (Security Update) — fixed build 17.0.4085.5
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67383
- patchhttps://www.microsoft.com/download/details.aspx?familyid=0d644af6-717c-45d7-bf71-ce7e309d2ad7
- referencehttps://support.microsoft.com/help/5122770
- patchhttps://www.microsoft.com/download/details.aspx?familyid=65b5f47b-53bf-4b54-89e7-6aefaad8dc51
- referencehttps://support.microsoft.com/help/5122769