Microsoft SQL Server (September 2026)

high Nessus Plugin ID 344796

Synopsis

The Microsoft SQL Server installation on the remote host is affected by multiple vulnerabilities.

Description

The Microsoft SQL Server installation on the remote host is missing security updates. It is, therefore, affected by multiple vulnerabilities:

- Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
(CVE-2026-77482)

- Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. (CVE-2026-77486)

- Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network. (CVE-2026-78442)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Microsoft has released the following security updates to address this issue:
-KB5122768
-KB5122769
-KB5122770
-KB5122771
-KB5122772
-KB5122773
-KB5122774
-KB5122775

See Also

https://support.microsoft.com/help/5122768

https://support.microsoft.com/help/5122769

https://support.microsoft.com/help/5122770

https://support.microsoft.com/help/5122771

https://support.microsoft.com/help/5122772

https://support.microsoft.com/help/5122773

https://support.microsoft.com/help/5122774

https://support.microsoft.com/help/5122775

Plugin Details

Severity: High

ID: 344796

File Name: smb_nt_ms26_sep_mssql_remote.nasl

Version: 1.1

Type: Remote

Family: Misc.

Published: 9/11/2026

Updated: 9/11/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.45

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-77482

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:microsoft:sql_server

Required KB Items: Settings/ParanoidReport

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 9/8/2026

Reference Information

CVE: CVE-2026-47297, CVE-2026-66814, CVE-2026-66816, CVE-2026-66818, CVE-2026-66819, CVE-2026-66820, CVE-2026-67368, CVE-2026-67369, CVE-2026-67370, CVE-2026-67373, CVE-2026-67376, CVE-2026-67378, CVE-2026-67379, CVE-2026-67380, CVE-2026-67381, CVE-2026-67383, CVE-2026-67384, CVE-2026-67385, CVE-2026-67386, CVE-2026-67388, CVE-2026-67389, CVE-2026-67390, CVE-2026-67393, CVE-2026-67624, CVE-2026-67629, CVE-2026-67630, CVE-2026-67631, CVE-2026-67633, CVE-2026-67636, CVE-2026-67638, CVE-2026-67639, CVE-2026-67641, CVE-2026-67642, CVE-2026-67643, CVE-2026-67645, CVE-2026-67648, CVE-2026-68775, CVE-2026-68776, CVE-2026-68777, CVE-2026-68778, CVE-2026-68779, CVE-2026-68780, CVE-2026-68781, CVE-2026-68784, CVE-2026-68785, CVE-2026-68786, CVE-2026-68787, CVE-2026-69562, CVE-2026-73028, CVE-2026-73029, CVE-2026-77480, CVE-2026-77481, CVE-2026-77482, CVE-2026-77483, CVE-2026-77484, CVE-2026-77485, CVE-2026-77486, CVE-2026-77487, CVE-2026-77488, CVE-2026-78441, CVE-2026-78442, CVE-2026-78456

CWE: 121, 122, 1220, 125, 126, 1390, 190, 191, 209, 269, 284, 416, 502, 59, 778, 822, 89, 908

MSFT: MS26-5122768, MS26-5122769, MS26-5122770, MS26-5122771, MS26-5122772, MS26-5122773, MS26-5122774, MS26-5122775

MSKB: 5122768, 5122769, 5122770, 5122771, 5122772, 5122773, 5122774, 5122775