{"id":"CVE-2026-67624","title":"Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.","summary":"Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-125"],"vendor":"Microsoft","product":"Microsoft SQL Server 2019 (CU 32)","affected":["sql_server_2019_cu_32 >= 15.0.0.0 < 15.0.4490.9","sql_server_2019_gdr >= 15.0.0 < 15.0.2190.7","sql_server_2022_cu_26 >= 16.0.0.0 < 16.0.4275.2","sql_server_2022_gdr >= 16.0.0 < 16.0.1200.5","sql_server_2025_cu8 >= 17.0.0.0 < 17.0.4085.5","sql_server_2025_for_x64-based_systems_gdr >= 17.0.1050.2 < 17.0.1135.8"],"published":"2026-09-08","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:18:11.277","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67624","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67624","label":"secure@microsoft.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T18:59:57.597935Z"},"ingestedAt":"2026-09-08T19:08:49.605Z","epss":0.00552,"epssPercentile":0.44985,"slug":"CVE-2026-67624","body":"## Overview\n\nOut-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}