Vulnerability
Published 2026-08-26
Verified 2026-09-19

Microsoft SQL Server remote code execution (CVE-2019-1068)

CISA added CVE-2019-1068 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD: a remote code execution issue when SQL Server incorrectly handles processing of internal functions. Apply the Microsoft security update from the MSRC advisory. Do not invent a cumulative update number here.

Product
Microsoft SQL Server
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
Microsoft security update (MSRC CVE-2019-1068)

Primary: Microsoft MSRC · Vendor: NVD · CVE: CVE-2019-1068 · CISA KEV addition notice

vulnerabilities