SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66819

HIGH · CVSS 8.8 EPSS 0.73%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in SQL Server that allows an authorized attacker to exploit improper handling of special elements in SQL commands, leading to SQL injection attacks. This can enable the attacker to elevate their privileges over the network, potentially compromising sensitive data and system integrity. Organizations using SQL Server should prioritize patching this vulnerability to mitigate the risk of unauthorized access and privilege escalation.

CVE
CVE-2026-66819
Severity
HIGH
CVSS
8.8
EPSS
0.73%

Original NVD Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)