CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft · SQL Server
Listed by CISA as exploited in the wild since 26 Aug 2026. Below: exploitation status, EPSS and every published CVSS, each with its source, then affected versions and references.
Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time
Description
as written by CISA (KEV catalog)
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
Required action
CISA KEV
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products and versions
CVE record · microsoft
Microsoft · Microsoft SQL Server 2014 Service Pack 2 for 32-bit Systems (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server
- affected: 2014 Service Pack 2 for 32-bit Systems (CU)
- affected: 2014 Service Pack 2 for x64-based Systems (CU)
- affected: 2016 for x64-based Systems Service Pack 1 (CU)
- affected: 2017 for x64-based Systems (CU)
- affected: 2016 for x64-based Systems Service Pack 2 (CU)
Microsoft · Microsoft SQL Server 2014 Service Pack 2 for x64-based Systems (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server 2016 for x64-based Systems Service Pack 1 (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server 2017 for x64-based Systems (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server 2016 for x64-based Systems Service Pack 2 (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server 2014 Service Pack 3 for x64-based Systems (CU)
- affected: unspecified
Microsoft · Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (GDR)
- affected: unspecified
Microsoft · Microsoft SQL Server 2014 Service Pack 3 for 32-bit Systems (CU)
- affected: unspecified
Status words (affected, unaffected, unknown) and version bounds are copied from the record. An upper bound such as “before 7.1.0” usually marks the first fixed version; confirm in the vendor advisory before planning an upgrade.
References
CISA KEV notes and CVE record
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2019-1068
EPSS over the last 30 days
See also: all Microsoft entries in KEV · the full KEV catalog
Related entries
Other Microsoft entries in KEV
- CVE-2026-65660Microsoft SharePoint Code Injection Vulnerability
- CVE-2026-85880Microsoft Windows Heap-Based Buffer Overflow Vulnerability
- CVE-2026-81963Microsoft Windows Link Following Vulnerability
- CVE-2026-55040Microsoft SharePoint Weak Authentication Vulnerability
- CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Added in the same week (see the week)
- CVE-2023-49105ownCloud Improper Authentication Vulnerability
- CVE-2026-53362Linux Kernel Unspecified Vulnerability
- CVE-2026-66384JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability
- CVE-2021-23758Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
- CVE-2015-3246Red Hat Libuser Race Condition Vulnerability
- CVE-2015-5287Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Questions about CVE-2019-1068
Is CVE-2019-1068 being exploited?
Yes, according to CISA. CVE-2019-1068 was added to the Known Exploited Vulnerabilities catalog on 26 Aug 2026, which CISA does only with reliable evidence of exploitation in the wild. The catalog field for ransomware campaign use says "Unknown".
What is the deadline to remediate CVE-2019-1068?
CISA set 29 Aug 2026 as the due date for US Federal Civilian Executive Branch agencies. The date is binding only for those agencies; other organisations can read it as a measure of urgency.
What is the EPSS score of CVE-2019-1068?
57.0%, in the 99.0th percentile, in the FIRST EPSS model of 2 Oct 2026. It estimates the probability of exploitation activity in the following 30 days. For a CVE already in KEV the score is secondary: exploitation has been observed.
How severe is CVE-2019-1068?
NVD rates it 8.8 HIGH (CVSS 3.1); CISA-ADP rates it 8.8 HIGH (CVSS 3.1). These are the published assessments as of 3 Oct 2026; this site does not rescore.
Which product does CVE-2019-1068 affect?
Microsoft SQL Server, as named in the CISA catalog. The affected versions listed in the CVE record are on this page; the vendor advisory in the references is the authority on fixed versions.
Related sections
- WatchlistWhat attackers started using this month, most urgent first.
- Exploited catalogEvery flaw CISA lists as used in real attacks (KEV), searchable.
- CVE lookupType one identifier: attack status, probability, severity, versions.
- Attack probabilityEPSS score for up to 100 identifiers at once.
- VendorsWhich vendors have the most exploited flaws.
- RSS and JSON feedsFollow new exploited flaws for the vendors you run.
- Sources and methodWhere each number comes from and how the order is decided.