sql_server_2022_cu_26 vulnerabilities
CVEs whose affected-version data names the sql_server_2022_cu_26 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-67630Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
▾ SunlitMicrosoft · Microsoft SQL Server 2017 (CU 31)EPSS 0.71%via NVD
CVE-2026-67629Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
▾ SunlitMicrosoft · Microsoft SQL Server 2017 (CU 31)EPSS 0.71%via NVD
CVE-2026-67624Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
▾ SunlitMicrosoft · Microsoft SQL Server 2019 (CU 32)EPSS 0.55%via NVD
CVE-2026-47297High· 8.1Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
▾ TwilightMicrosoft · Microsoft SQL Server 2019 (CU 32)EPSS 0.84%via NVD