CISA Warns of Critical SQL Server Vulnerability Exploitation
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft SQL Server vulnerability to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2019-1068, allows an attacker to execute code under the permissions of the SQL Server Database Engine service account.
Successful exploitation could grant an attacker the ability to run malicious commands on a vulnerable database server, with the level of access depending on the privileges assigned to the SQL Server service account. Systems configured with highly privileged service accounts may face a greater impact as the attacker could potentially move beyond the database environment and affect the underlying Windows host.
CISA added the vulnerability to its catalog on August 26, 2026, and set an August 29, 2026, remediation deadline. The agency has also marked the issue as requiring forensic triage under Binding Operational Directive 26-04, signaling that organizations should not treat patching as the only required response.
Security teams are advised to investigate potentially affected SQL Server environments for evidence of prior compromise before or alongside mitigation work. While the vulnerability is not currently known to have been used in ransomware campaigns, it poses a significant risk due to the sensitive nature of data stored in SQL Server instances and their attractiveness to threat actors seeking initial access, opportunities for credential theft, lateral movement, or data theft.