CVE-2026-78456HighCVSS 8.8
SQL Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
🎯 Affected products2
- Microsoft SQL Server 2022 for x64-based Systems (CU 26)
- Microsoft SQL Server 2022 for x64-based Systems (GDR)
✅ Remediation
KB5122768 (Security Update) — fixed build 16.0.4275.2 KB5122771 (Security Update) — fixed build 16.0.1200.5
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78456
- patchhttps://www.microsoft.com/download/details.aspx?familyid=d682ec86-56e1-45c3-a0fa-552f89f6e51e
- referencehttps://support.microsoft.com/help/5122768
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7ce0ba48-9a1e-4298-b300-79f251385092
- referencehttps://support.microsoft.com/help/5122771