CVE-2026-68782: Microsoft Azure SQL Database

Critical severity, CVSS 9.9. EPSS: 1% chance of exploitation in the next 30 days.

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Affected products

  • Microsoft Azure SQL Database: affected versions not specified

Published 2026-08-20. Last modified 2026-08-24.