CVE-2019-1068CISA KEV
Microsoft SQL Server Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
- Product
- SQL Server
- Added to KEV
- 26 Aug 2026
- Federal remediation due
- 29 Aug 2026
- Known ransomware use
- Not reported