Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* |
Wed, 09 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr) Microsoft microsoft Sql Server 2022 (gdr) Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr) |
|
| Vendors & Products |
Microsoft microsoft Sql Server 2017 (gdr)
Microsoft microsoft Sql Server 2019 (gdr) Microsoft microsoft Sql Server 2022 (gdr) Microsoft microsoft Sql Server 2025 For X64-based Systems (gdr) |
Tue, 08 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | |
| Title | SQL Server Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft sql Server 2017 Microsoft sql Server 2019 Microsoft sql Server 2022 Microsoft sql Server 2025 |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:microsoft:sql_server_2017:*:-:*:*:*:*:x64:* cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:sql_server_2022:*:*:*:*:*:*:x64:* cpe:2.3:a:microsoft:sql_server_2025:*:*:*:*:*:*:x64:* |
|
| Vendors & Products |
Microsoft
Microsoft sql Server 2017 Microsoft sql Server 2019 Microsoft sql Server 2022 Microsoft sql Server 2025 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-09-16T21:54:25.697Z
Reserved: 2026-07-27T19:02:26.601Z
Link: CVE-2026-66820
Updated: 2026-09-09T09:59:23.948Z
Status : Analyzed
Published: 2026-09-08T18:18:20.420
Modified: 2026-09-16T12:00:10.167
Link: CVE-2026-66820
No data.
OpenCVE Enrichment
Updated: 2026-09-08T19:45:04Z