A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.
https://securityaffairs.com/197975/hacking/u-s-cisa-adds-red-hat-linux-kernel-ajax-net-professional-microsoft-sql-server-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://www.infosecurity-magazine.com/news/cisa-kev-microsoft-citrix/
https://www.helpnetsecurity.com/2026/08/27/netscaler-adc-gateway-cve-2026-8452/
https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html
https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
https://securelist.com/mallox-ransomware/113529/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1068
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1068
Source: Mitre, NVD
Published: 2019-07-15
Updated: 2026-08-27
Known Exploited Vulnerability (KEV)
Base Score: 6.5
Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P
Severity: Medium
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.52845