| CVE | CVE-2019-1068 |
| Vulnerability Name | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVSS Score / Version | 8.8 (High) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Microsoft SQL Server, Microsoft SQL Server 2016, and Microsoft SQL Server 2017 |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-08-26. |
| Exploitation prediction (EPSS) | 57.91% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-08-29 (CISA KEV, Binding Operational Directive). |
A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
Monitor Microsoft's web page for any future patch releases.