← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 27, 2026 · 15:49via Cyber Security News

CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks

Brief

The U. S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability , tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.

The flaw affects Microsoft SQL Server and can allow an attacker to execute code under the permissions of the SQL Server Database Engine service account. CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server.

Successful exploitation could allow an attacker to run malicious commands on a vulnerable database server, with the level of access depending on the privileges assigned to the SQL Server service account.

Systems configured with highly privileged service accounts may face a greater impact because the attacker could potentially move beyond the database environment and affect the underlying Windows host.

Read more on Cyber Security News