Skip to main content
QUIETLYTIC
Vulnerability

Microsoft SQL Server Vulnerability (CVE-2019-1068)

CVE-2019-1068 is a 2019 CVSS 8.8 remote code execution flaw in Microsoft SQL Server, added to CISA KEV in August 2026 for newly observed exploitation.

CVE-2019-1068
Threat Level
HIGH
CVSS
8.8
Status
Active Exploitation
Confidence
High
Affected Products
Microsoft SQL Server

CVE-2019-1068 carries a CVSS 3.1 base score of 8.8 against Microsoft SQL Server. NVD classifies it as CWE-20 (Improper Input Validation). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 26, 2026 — confirming exploitation directly through CISA’s own listing process, more than seven years after this vulnerability was originally disclosed in July 2019.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

NVD’s description is brief and follows Microsoft’s original 2019 advisory language: a remote code execution vulnerability exists when SQL Server incorrectly handles the processing of internal functions. NVD does not name the specific internal function or the exact code path involved beyond that summary; Microsoft’s own security advisory, linked from NVD’s record, is the authoritative technical source, but our source data does not carry deeper mechanism detail from it.

We report NVD’s classification as stated rather than speculating about the missing technical detail behind a description this brief.

Evidence and confidence

  • High confidence — exploitation status, sourced directly from CISA KEV, which our evidence model treats as an authoritative single source for this specific field.
  • Medium confidence — the CVSS 8.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and the CWE-20 classification, which trace to NVD alone in our current ingestion.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.52845, a 98.9th percentile score as of our ingestion — among the highest we have seen in our recent KEV coverage.

No field is in conflict between our two sources. Our data carries no fixed-version field; consult Microsoft’s own security advisory directly for patch guidance.

Why this matters

A 2019-disclosed vulnerability appearing on CISA’s KEV catalog in 2026 is not evidence of a newly discovered flaw — it typically reflects newly observed exploitation of deployments that were never patched in the intervening years, a pattern this publication has covered before with other long-unpatched software. SQL Server installations are frequently treated as stable, infrequently touched infrastructure once deployed, which can mean patch cycles lag well behind newly disclosed vulnerabilities, let alone one that’s over seven years old and easy to assume is no longer relevant.

The near-maximal EPSS percentile (98.9th) combined with CISA’s direct confirmation of exploitation makes clear this is not a dormant, historical CVE — it is an actively exploited one today, and any organization running an unpatched, affected SQL Server version should treat this with the same urgency as a newly disclosed critical flaw.

Frequently Asked Questions

What is CVE-2019-1068? A CVSS 8.8 remote code execution vulnerability (CWE-20) in Microsoft SQL Server, originally disclosed in July 2019, involving incorrect handling of internal function processing.

Is CVE-2019-1068 being actively exploited? Yes, per CISA’s own Known Exploited Vulnerabilities catalog, which added this CVE on August 26, 2026 — this is a higher-confidence exploitation claim than a VulnCheck-only listing, since CISA KEV is treated as an authoritative source in our evidence model.

Why is a 2019 CVE showing up in a 2026 KEV feed? CISA added it to its Known Exploited Vulnerabilities catalog in August 2026 — over seven years after initial disclosure — which typically reflects newly observed exploitation of deployments that were never patched, not a new vulnerability.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which version fixes this? Our data carries no fixed-version field. Consult Microsoft’s own security advisory directly for the specific patch matching your SQL Server version.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2019-1068. Exploitation status and the August 26, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry. Microsoft’s own security advisory: MSRC guidance for CVE-2019-1068. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools