All incidents

CISA adds Microsoft SQL Server RCE flaw (CVE-2019-1068) to KEV list

vulnerabilityopenAug 26, 2026 — Aug 27, 2026

CISA has added CVE‑2019‑1068 to its Known Exploited Vulnerabilities catalogue, flagging a remote code execution flaw in Microsoft SQL Server as actively exploited in the wild. The vulnerability permits an attacker to run arbitrary code with the privileges of the SQL Server Database Engine service account. Its inclusion means organisations must treat the issue as a priority for patching under federal binding directives. Security teams should consult the catalogue to understand the risk and prioritise remediation.

Tracked as CVE‑2019‑1068, the flaw carries a CVSS base score of 8.8 and is rated HIGH. It can be triggered over the network without authentication, allowing an unauthenticated attacker to send specially crafted packets to the SQL Server port and gain execution within the database engine process. The attack may be launched directly against port 1433 or leveraged through SQL injection footholds that reach the underlying service. Successful exploitation grants full control of the affected SQL Server instance, enabling data theft, lateral movement or ransomware deployment.

Microsoft SQL Server releases from 2008 R2 through 2017 are affected, though the exact list of vulnerable editions is detailed in the vendor’s advisory. A security update that addresses the issue has been released and is available for download through the Microsoft Security Response Center. The patch corrects the flawed handling of specially crafted requests within the Database Engine component. Administrators should confirm that the update matches their specific version and edition before applying it, and test it in a non‑production environment first.

The addition to the KEV catalogue indicates that CISA has observed real‑world exploitation of this vulnerability, although no specific threat actors have been publicly linked to the campaign. Researchers have noted that exploit code for CVE‑2019‑1068 is publicly available and has been incorporated into automated scanning tools. Such tools are often used by opportunistic actors to locate exposed SQL Server instances on the internet. Once compromised, attackers frequently use the foothold to deploy ransomware or exfiltrate sensitive databases.

Defenders should prioritise installing the Microsoft patch for CVE‑2019‑1068, verifying applicability to their SQL Server build and edition as advised in the vendor’s guidance. Where immediate patching is not feasible, organisations should restrict network access to the SQL Server port, allowing only trusted IP addresses, and enable strong authentication for any remaining access. It is also advisable to disable unnecessary protocols such as the SQL Server Browser service if not required for functionality. Regularly reviewing patch levels and subscribing to vendor security notifications helps close the window of exposure.

Additionally, reviewing service account permissions to ensure the SQL Server Database Engine runs with least privilege can limit the impact of a successful exploit. Enabling detailed logging and monitoring for anomalous queries or unexpected process behaviour helps detect early signs of compromise. Network segmentation that isolates database tiers from application and web tiers reduces the lateral movement potential after a breach. Keeping abreast of updates in the CISA KEV catalogue ensures that other actively exploited weaknesses are not overlooked.

Intelligence briefing updated Aug 27, 2026

CVE-2019-1068 8.8 KEV
Root sourceportal.msrc.microsoft.com
Timeline Coverage

Swipe to explore timeline