CISA has added CVE‑2019‑1068 to its Known Exploited Vulnerabilities catalogue. The flaw affects Microsoft SQL Server and is named the Microsoft SQL Server Remote Code Execution Vulnerability. In brief, the vulnerability allows an attacker to execute arbitrary code in the context of the SQL Server Database Engine service account.
The issue is a remote code execution vulnerability in Microsoft SQL Server. It carries a CVSS base score of 8.8, rated HIGH, and can be exploited over the network without authentication, leading to full control of the affected database engine process. Microsoft has released a security update that patches the flaw. Administrators should verify the applicability of the update to their specific SQL Server version and edition before deployment.
Because the vulnerability is listed in the KEV catalogue, active exploitation has been observed in the wild. No public reports link this CVE to ransomware campaigns at present. CISA has set a remediation deadline of 29 August 2026 for federal civilian executive branch agencies to address the issue.
CISA requires that agencies apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.
While the directive binds FCEB agencies, all organisations should review their SQL Server deployments for exposure and apply the available patch promptly. Organisations should also consider network segmentation and least‑privilege principles to limit potential impact.
For full technical details, consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2019-1068 and the CISA KEV catalogue.