As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0350 [1.00] [M/H] Kwetsbaarheden verholpen in SQL Server
Microsoft released patches for 62 vulnerabilities across SQL Server and Windows OLE DB on September 8, 2026. The flaws include multiple remote code execution (RCE), privilege escalation, information disclosure, and denial of service (DoS) issues with CVSS scores ranging from 4.9 to 8.8. Key CVEs include CVE-2026-47297, CVE-2026-66814, CVE-2026-67373, CVE-2026-67378, CVE-2026-67379, CVE-2026-67380, CVE-2026-67384, CVE-2026-67385, CVE-2026-67388, CVE-2026-67631, CVE-2026-67636, CVE-2026-67638, CVE-2026-67639, CVE-2026-67642, CVE-2026-67643, CVE-2026-68775, CVE-2026-68786, CVE-2026-77481, CVE-2026-77482, CVE-2026-77484, CVE-2026-77486, CVE-2026-78442, and CVE-2026-78456.
Why it matters: Organizations running SQL Server must prioritize patching the 23 critical RCE and privilege escalation flaws to prevent remote compromise and lateral movement within database infrastructure.
- Source published
- First seen by Cybersecurity Tracker