CVE-2019-1068: Microsoft SQL Server Remote Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2026-08-26. EPSS: 57.3% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

Affected products

  • Microsoft SQL Server: version 2014 only
  • Microsoft SQL Server 2016: from 13.0.4001.0, before 13.0.4259.0 (fixed in 13.0.4259.0); from 13.0.4411.0, before 13.0.4604.0 (fixed in 13.0.4604.0); from 13.0.5026.0, before 13.0.5101.9 (fixed in 13.0.5101.9); from 13.0.5149.0, before 13.0.5366.0 (fixed in 13.0.5366.0)
  • Microsoft SQL Server 2017: from 14.0.1000.169, before 14.0.2027.2 (fixed in 14.0.2027.2); from 14.0.3006.16, before 14.0.3192.2 (fixed in 14.0.3192.2)

Published 2019-07-15. Last modified 2026-08-27.