VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Patches 62 SQL Server Vulnerabilities

routine vulnerability

NCSC-NL advisory details 62 Microsoft SQL Server and Windows OLE DB flaws, many enabling remote code execution or privilege escalation; patches available, no active exploitation reported.

NCSC-NL (Dutch national CERT) published an advisory summarizing 62 vulnerabilities that Microsoft has patched across SQL Server components and the Windows OLE DB provider used by SQL Server. The flaw classes include SQL injection, stack- and heap-based buffer overflows, use-after-free, deserialization of untrusted data, integer overflow/underflow, out-of-bounds read, untrusted pointer dereference, weak authentication, and insufficient access-control granularity. Impact categories span arbitrary code execution, privilege escalation, security-control bypass, sensitive information disclosure, and denial-of-service. Many of the higher-severity issues (CVSS 8.5-8.8) allow remote code execution or elevation of privilege, indicating an attacker with database access or the ability to submit crafted queries/input could potentially gain code execution or higher privileges on the SQL Server host.

No indication is given in the advisory of active exploitation in the wild; this is a routine vendor patch release consolidated into a single NCSC bulletin. Defenders running Microsoft SQL Server (all supported versions per Microsoft's Security Update Guide) and systems relying on Windows OLE DB should prioritize testing and deploying the referenced Microsoft updates, particularly for instances exposed to untrusted networks or multi-tenant environments where SQL injection or privilege-escalation vectors could be reached by lower-privileged users. Full technical details, affected product/version matrices, and update packages are available via the Microsoft Security Response Center portal linked in the advisory.

Mentioned in this report

Vulnerabilities CVE-2026-47297CVE-2026-66814CVE-2026-66816CVE-2026-66818CVE-2026-66819CVE-2026-66820CVE-2026-67368CVE-2026-67369CVE-2026-67370CVE-2026-67373CVE-2026-67376CVE-2026-67378CVE-2026-67379CVE-2026-67380CVE-2026-67381CVE-2026-67383CVE-2026-67384CVE-2026-67385CVE-2026-67388CVE-2026-67631CVE-2026-67636CVE-2026-67638CVE-2026-67639CVE-2026-67642CVE-2026-67643CVE-2026-68775CVE-2026-68786CVE-2026-68787CVE-2026-73028CVE-2026-77480CVE-2026-77481CVE-2026-77482CVE-2026-77483CVE-2026-77484CVE-2026-77485CVE-2026-77486CVE-2026-77487CVE-2026-78441CVE-2026-78442CVE-2026-78456

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0350.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free