Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33120

37
FAUCET Score

CVE-2026-33120 is an untrusted pointer dereference vulnerability in SQL Server that permits authorized attackers to execute arbitrary code remotely over a network. This vulnerability affects SQL Server systems and requires valid user credentials to exploit, limiting the attack surface to authenticated users with network access. The vulnerability carries a CVSS severity rating of 8.8 (HIGH) with a network attack vector and low attack complexity, indicating that exploitation can be executed easily once authentication is obtained. The impact is severe across all three security dimensions: confidentiality, integrity, and availability are all rated as high, meaning successful exploitation could lead to complete system compromise. Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed on the KEV catalog and is marked as inactive on threat intelligence tracking lists. The EPSS score of 0.0007 suggests minimal real-world exploitation probability to date, though organizations should still prioritize patching given the high CVSS severity rating and complete impact potential.

Impacted Technologies

VendorProductVersion(s)CPE
>= 13.0.6300.2, < 13.0.6485.1CPE matchmatch criteria
cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:*
>= 13.0.7000.253, < 13.0.7080.1CPE matchmatch criteria
cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:*
>= 14.0.1000.169, < 14.0.2105.1CPE matchmatch criteria
cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*
>= 14.0.3006.16, < 14.0.3525.1CPE matchmatch criteria
cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:*
>= 15.0.2000.5, < 15.0.2165.1CPE matchmatch criteria
cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0071 is in the 42nd percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft SQL Server 2022 for x64-based Systems (GDR)Fixed in: 16.0.1175.1
View patch
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-33120Important

Microsoft SQL Server Remote Code Execution Vulnerability

Apr 14, 2026

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2026-33120
Vendor Advisory