SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-67370

HIGH · CVSS 8.8 EPSS 0.67%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in SQL Server allows authorized attackers to exploit improper neutralization of special elements in SQL commands, leading to SQL injection attacks that can elevate their privileges over a network. Organizations utilizing SQL Server should prioritize addressing this issue to mitigate the risk of unauthorized access and potential data breaches. Immediate action is recommended for those managing sensitive data or critical applications relying on this database technology.

CVE
CVE-2026-67370
Severity
HIGH
CVSS
8.8
EPSS
0.67%

Original NVD Description

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)