CVE-2026-78456HighCVSS 8.8

SQL Server Remote Code Execution Vulnerability

Published
September 11, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

🎯 Affected products2

  • Microsoft SQL Server 2022 for x64-based Systems (CU 26)
  • Microsoft SQL Server 2022 for x64-based Systems (GDR)

✅ Remediation

KB5122768 (Security Update) — fixed build 16.0.4275.2 KB5122771 (Security Update) — fixed build 16.0.1200.5

🔗 References (5)