Vulnerability
Published 2026-08-26
Verified 2026-09-19
Microsoft SQL Server remote code execution (CVE-2019-1068)
CISA added CVE-2019-1068 to KEV on 26 August 2026 (federal due date 29 August 2026). NVD: a remote code execution issue when SQL Server incorrectly handles processing of internal functions. Apply the Microsoft security update from the MSRC advisory. Do not invent a cumulative update number here.
- Product
- Microsoft SQL Server
- CVSS
- (CVSS 3.1, NVD)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Microsoft security update (MSRC CVE-2019-1068)
Primary: Microsoft MSRC · Vendor: NVD · CVE: CVE-2019-1068 · CISA KEV addition notice
