CVE-2026-77486HighCVSS 8.8
Microsoft SQL Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
🎯 Affected products4
- Microsoft SQL Server 2017 for x64-based Systems (CU 31)
- Microsoft SQL Server 2017 for x64-based Systems (GDR)
- Microsoft SQL Server 2019 for x64-based Systems (CU 32)
- Microsoft SQL Server 2019 for x64-based Systems (GDR)
✅ Remediation
KB5122775 (Security Update) — fixed build 14.0.2130.4 KB5122773 (Security Update) — fixed build 15.0.2190.7 KB5122774 (Security Update) — fixed build 14.0.3550.4 KB5122772 (Security Update) — fixed build 15.0.4490.9
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77486
- patchhttps://www.microsoft.com/download/details.aspx?familyid=bd775fa7-3414-4aeb-9309-4e0b90d4d1ee
- referencehttps://support.microsoft.com/help/5122775
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e668fe5f-ea1e-41fb-97f7-1bc12e91150b
- referencehttps://support.microsoft.com/help/5122773
- patchhttps://www.microsoft.com/download/details.aspx?familyid=a2440065-e61a-43ec-96a2-a5ee18f7fc19
- referencehttps://support.microsoft.com/help/5122774
- patchhttps://www.microsoft.com/download/details.aspx?familyid=cee52a4a-832a-447e-909d-0f629cab835f
- referencehttps://support.microsoft.com/help/5122772