Microsoft disclosed a broad set of vulnerabilities affecting the SQL Server ecosystem, including remote code execution, elevation of privilege, and information disclosure issues across SQL Server Native Client, Microsoft ODBC Driver for SQL Server, core Microsoft SQL Server components, and Microsoft.SqlServer.XEvent.Configuration.dll. The largest group of advisories covered SQL Server Native Client RCE flaws, including CVE-2024-38255, CVE-2024-43459, CVE-2024-43462, CVE-2024-48993, CVE-2024-48995, CVE-2024-48996, CVE-2024-48997, CVE-2024-48998, CVE-2024-48999, CVE-2024-49000, CVE-2024-49004, CVE-2024-49005, and CVE-2024-49007. Microsoft also listed CVE-2024-49043 as an RCE flaw in Microsoft.SqlServer.XEvent.Configuration.dll and earlier ODBC driver RCE bugs CVE-2023-36730 and CVE-2023-36785.
Additional SQL Server issues included Native Scoring RCE vulnerabilities CVE-2024-26186 and CVE-2024-37338, Native Scoring information disclosure flaws CVE-2024-37342 and CVE-2024-37966, SQL Server elevation of privilege bugs CVE-2024-37965, CVE-2024-37341, CVE-2024-37980, and CVE-2026-26116, plus a general SQL Server information disclosure issue tracked as CVE-2024-43474. The disclosures show Microsoft addressing repeated attack surface in SQL Server connectivity layers and supporting components, underscoring the need for organizations running SQL Server clients, drivers, and related libraries to prioritize vendor updates across both server-side and workstation-deployed software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
Microsoft published a Security Update Guide entry for CVE-2026-33120, a remote code execution vulnerability affecting Microsoft SQL Server. The advisory included guidance for applying the appropriate security updates across supported SQL Server versions and servicing tracks.
Microsoft released a Security Update Guide entry for CVE-2026-32176, an elevation of privilege vulnerability affecting SQL Server. The advisory was published as part of Microsoft's 2026-04-14 security updates.
Microsoft released a Security Update Guide entry for CVE-2026-32167, an elevation of privilege vulnerability affecting SQL Server.
Microsoft released a Security Update Guide entry for CVE-2026-26116, an elevation of privilege vulnerability affecting SQL Server.
Microsoft released a Security Update Guide entry for CVE-2025-55227, an elevation of privilege vulnerability affecting Microsoft SQL Server. The advisory was published on 2025-09-09.
Microsoft published a Security Update Guide entry for CVE-2025-47997, an information disclosure vulnerability affecting Microsoft SQL Server. The advisory was released on 2025-09-09.
Microsoft published a Security Update Guide entry for CVE-2025-49719, an information disclosure vulnerability affecting Microsoft SQL Server. The advisory was released on 2025-07-08.
Microsoft published a Security Update Guide entry for CVE-2025-49717, a remote code execution vulnerability affecting Microsoft SQL Server. The advisory was released on 2025-07-08.
Microsoft published Security Update Guide entry CVE-2024-49043, a remote code execution vulnerability in Microsoft.SqlServer.XEvent.Configuration.dll, as part of its November 2024 releases.
Microsoft published a large set of Security Update Guide entries for SQL Server Native Client remote code execution vulnerabilities, including CVE-2024-38255, CVE-2024-43459, CVE-2024-43462, CVE-2024-48993, CVE-2024-48995, CVE-2024-48996, CVE-2024-48997, CVE-2024-48998, CVE-2024-48999, CVE-2024-49000, CVE-2024-49004, CVE-2024-49005, and CVE-2024-49007.
Microsoft published a Security Update Guide entry for CVE-2024-37340, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.
Microsoft published a Security Update Guide entry for CVE-2024-37339, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.
Microsoft published a Security Update Guide entry for CVE-2024-37335, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.
Microsoft published a Security Update Guide entry for CVE-2024-26191, a remote code execution vulnerability affecting Microsoft SQL Server Native Scoring. The advisory was released as part of Microsoft's September 2024 security updates.
Microsoft published multiple SQL Server-related advisories covering remote code execution, elevation of privilege, and information disclosure issues, including CVE-2024-26186, CVE-2024-37338, CVE-2024-37341, CVE-2024-37342, CVE-2024-37965, CVE-2024-37966, CVE-2024-37980, and CVE-2024-43474.
Microsoft published a Security Update Guide entry for CVE-2023-36728, a denial of service vulnerability affecting Microsoft SQL Server. The advisory was released on 2023-10-10.
Microsoft published a Security Update Guide entry for CVE-2023-36417, a remote code execution vulnerability affecting Microsoft SQL OLE DB. The advisory was released on 2023-10-10.
Microsoft published Security Update Guide entries for CVE-2023-36730 and CVE-2023-36785, both remote code execution vulnerabilities affecting the Microsoft ODBC Driver for SQL Server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
49 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceportal.msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.