๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
Summary
Microsoft SQL Server has a remote code execution vulnerability (RCE, where an attacker can run commands on a system they don't own) that lets attackers execute code using the SQL Server service account's permissions. This vulnerability is actively being exploited by attackers. Organizations must apply mitigations from Microsoft and follow CISA's BOD 26-04 guidance on prioritizing security updates, with a deadline of August 29, 2026.
Solution / Mitigation
Apply mitigations in accordance with vendor (Microsoft) instructions while ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines. See Microsoft Security Response Center (MSRC) advisory at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068 for specific patch details.
Vulnerability Details
EPSS: 44.7%
Yes
๐ฅ Actively Exploited
August 25, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2019-1068
First tracked: August 26, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%