Microsoft disclosed CVE-2026-77487, an SQL Server improper-access-control vulnerability with a CVSS 3.1 base score of 8.8. An authenticated attacker who already has explicit SQL Server permissions can connect over the network and elevate privileges to the sysadmin role, potentially affecting confidentiality, integrity, and availability. Microsoft reported no known public disclosure or active exploitation and assessed exploitation as less likely.
Microsoft has issued fixes through SQL Server servicing releases, including the SQL Server 2017 CU31 GDR security update (KB5122774). Organizations should promptly apply the current GDR/CU package for each supported SQL Server deployment, prioritize instances where non-administrative users have network access, and review SQL permissions to limit unnecessary authenticated access. SQL Server 2017 CU31 and SQL Server 2019 CU32 are their final cumulative updates; those versions will continue receiving applicable security and GDR fixes under lifecycle and extended-support terms.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft documented CVE-2026-77487, an improper-access-control flaw that allows an authenticated user with explicit SQL Server permissions to elevate privileges to SQL sysadmin over the network. Microsoft rated it CVSS 8.8, stated that an official fix was available, and reported no known public disclosure or in-the-wild exploitation at original publication.
Microsoft released SQL Server 2025 CU 8 GDR (KB5122769), SQL Server 2022 CU 26 GDR (KB5122768), SQL Server 2019 CU 32 GDR (KB5122772), and SQL Server 2017 CU 31 GDR (KB5122774) for Linux. The 2019 and 2017 releases were designated the final cumulative updates for those respective versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
learn.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcelearn.microsoft.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.