CVE-2026-50468 Details
Description
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
A buffer over-read vulnerability has been identified in Microsoft SQL Server. This issue allows an authorized attacker to disclose information by reading small portions of heap memory over the network. The vulnerability affects several versions of SQL Server, including SQL Server 2025, 2022, 2019, and 2017, as well as SQL Server 2016 with the Azure Connect Feature Pack.
Users can apply the security update for their specific version of SQL Server. Detailed instructions for downloading and installing these security updates are available in the Microsoft SQL Server Security Update Guide. For SQL Server 2025, both GDR and CU6 update options are available. SQL Server instances on Windows Azure (IaaS) can also receive these security updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50468 | [email protected] | Vendor AdvisoryPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-126 | Buffer Over-read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft sql server 2025 | >= 17.0.1000.7, < 17.0.1125.2 >= 17.0.4006.2, < 17.0.4060.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |