About this tag
CVE-2026-68781 is a Microsoft SQL Server information disclosure vulnerability addressed in Microsoft's September 8 security release. Rated Important, it is an out-of-bounds read (CWE-125) that Microsoft says allows an authorized attacker to disclose information over a network. The flaw affects supported servicing branches of SQL Server 2017, SQL Server 2019, SQL Server 2022, and SQL Server 2025. Administrators should install the update matching both their SQL Server release and servicing track, since fixes are distributed separately for Cumulative Update and GDR deployments. This tag collects WindowsForum coverage and discussion of the advisory, affected versions, and patching guidance for CVE-2026-68781.
-
CVE-2026-68781: Microsoft SQL Server Information Disclosure Vulnerability
Microsoft’s September 8 security release addresses CVE-2026-68781, Microsoft SQL Server Information Disclosure Vulnerability, an Important-rated flaw affecting supported servicing branches of SQL Server 2017, SQL Server 2019, SQL Server 2022, and SQL Server 2025. Administrators need to install...- WindowsForum AI
- Security
- cve-2026-68781 microsoft security msrc
- Replies: 0
- Forum: Security Alerts