# Microsoft Patches 62 SQL Server Vulnerabilities

Published: 2026-09-08 · Severity: routine
Canonical: https://vorant.io/reports/390d642a-0af1-5be2-a8ec-edc213cb4d60/microsoft-patches-62-sql-server-vulnerabilities

> NCSC-NL advisory details 62 Microsoft SQL Server and Windows OLE DB flaws, many enabling remote code execution or privilege escalation; patches available, no active exploitation reported.

NCSC-NL (Dutch national CERT) published an advisory summarizing 62 vulnerabilities that Microsoft has patched across SQL Server components and the Windows OLE DB provider used by SQL Server. The flaw classes include SQL injection, stack- and heap-based buffer overflows, use-after-free, deserialization of untrusted data, integer overflow/underflow, out-of-bounds read, untrusted pointer dereference, weak authentication, and insufficient access-control granularity. Impact categories span arbitrary code execution, privilege escalation, security-control bypass, sensitive information disclosure, and denial-of-service. Many of the higher-severity issues (CVSS 8.5-8.8) allow remote code execution or elevation of privilege, indicating an attacker with database access or the ability to submit crafted queries/input could potentially gain code execution or higher privileges on the SQL Server host.

No indication is given in the advisory of active exploitation in the wild; this is a routine vendor patch release consolidated into a single NCSC bulletin. Defenders running Microsoft SQL Server (all supported versions per Microsoft's Security Update Guide) and systems relying on Windows OLE DB should prioritize testing and deploying the referenced Microsoft updates, particularly for instances exposed to untrusted networks or multi-tenant environments where SQL injection or privilege-escalation vectors could be reached by lower-privileged users. Full technical details, affected product/version matrices, and update packages are available via the Microsoft Security Response Center portal linked in the advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-47297, CVE-2026-66814, CVE-2026-66816, CVE-2026-66818, CVE-2026-66819, CVE-2026-66820, CVE-2026-67368, CVE-2026-67369, CVE-2026-67370, CVE-2026-67373, CVE-2026-67376, CVE-2026-67378, CVE-2026-67379, CVE-2026-67380, CVE-2026-67381, CVE-2026-67383, CVE-2026-67384, CVE-2026-67385, CVE-2026-67388, CVE-2026-67631, CVE-2026-67636, CVE-2026-67638, CVE-2026-67639, CVE-2026-67642, CVE-2026-67643, CVE-2026-68775, CVE-2026-68786, CVE-2026-68787, CVE-2026-73028, CVE-2026-77480, CVE-2026-77481, CVE-2026-77482, CVE-2026-77483, CVE-2026-77484, CVE-2026-77485, CVE-2026-77486, CVE-2026-77487, CVE-2026-78441, CVE-2026-78442, CVE-2026-78456

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0350.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/390d642a-0af1-5be2-a8ec-edc213cb4d60/microsoft-patches-62-sql-server-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
