Cyber Security News

CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability, tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.

The flaw affects Microsoft SQL Server and can allow an attacker to execute code under the permissions of the SQL Server Database Engine service account. CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server.

Successful exploitation could allow an attacker to run malicious commands on a vulnerable database server, with the level of access depending on the privileges assigned to the SQL Server service account.

Systems configured with highly privileged service accounts may face a greater impact because the attacker could potentially move beyond the database environment and affect the underlying Windows host. CISA added the vulnerability to its catalog on August 26, 2026, and set an August 29, 2026, remediation deadline.

The agency has also marked the issue as requiring forensic triage under Binding Operational Directive 26-04, signaling that organizations should not treat patching as the only required response.

Microsoft SQL Server RCE Vulnerability Exploited

Security teams should investigate potentially affected SQL Server environments for evidence of prior compromise before or alongside mitigation work. The agency said the vulnerability is not currently known to have been used in ransomware campaigns.

However, this designation does not reduce the urgency of remediation, as SQL Server instances often store sensitive business data and are attractive targets for threat actors seeking initial access, opportunities for credential theft, lateral movement, or data theft.

Organizations should apply Microsoft’s recommended mitigations and ensure their response aligns with CISA’s risk-based patching requirements.

Administrators should identify all affected SQL Server assets, determine whether they are exposed to the internet, and prioritize externally accessible or business-critical systems. Where patches or mitigations are not available, CISA advises organizations to discontinue use of the affected product.

Forensic triage should include reviewing SQL Server logs, Windows event logs, endpoint detection alerts, database audit records, suspicious service-account activity, unexpected process execution, and unusual outbound network connections from database servers.

Security teams should also check for newly created accounts, modified scheduled tasks, web shells, unauthorized database jobs, or changes to SQL Server Agent configurations.

Because exploitation enables code execution in the SQL Server Database Engine service context, defenders should verify that SQL Server services do not run with excessive privileges.

Applying least-privilege controls, restricting SQL Server network exposure, segmenting database systems, and monitoring administrative activity can reduce the damage if a vulnerability is exploited.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago