CVE-2026-21262Patch(microsoft / sql_server_2016)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 23 mentions and remains active

Immediate actions

  • Patch microsoft sql_server_2016 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sql_server_2016
  • sql_server_2017
  • sql_server_2019
  • sql_server_2022

Threat summary

  • Active exploitation appears in 8 classified signals
  • Patch or workaround signal is available
  • 88 mentions across 30 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 8 signals
  • Patch or workaround mentioned in 66 signals
  • Technical details provided in 59 signals
  • Disclosure: 12 classified signals
  • General: 8 classified signals
  • Peaked 28d ago at 23 mentions (2026-03-11); latest day: 1
  • 88 total mentions across 30 days

Affected systems

Vendors
Products
sql_server_2016sql_server_2017sql_server_2019sql_server_2022sql_server_2025

Deep dive

Activity timeline88 mentions / 30d
06121723Mentions · 2026-03-10: 7Mentions · 2026-03-11: 23Mentions · 2026-03-12: 14Mentions · 2026-03-13: 5Mentions · 2026-03-14: 2Mentions · 2026-03-16: 4Mentions · 2026-03-17: 4Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-20: 2Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-03-26: 3Mentions · 2026-03-27: 2Mentions · 2026-03-29: 2Mentions · 2026-04-01: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Mentions · 2026-04-05: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1Mentions · 2026-04-14: 1Mentions · 2026-04-22: 1Mentions · 2026-05-05: 1Mentions · 2026-05-10: 1Mentions · 2026-06-02: 1Mentions · 2026-06-16: 1Mentions · 2026-06-23: 1Mentions · 2026-09-22: 1Active Exploitation · 2026-03-11: 4Active Exploitation · 2026-03-12: 2Active Exploitation · 2026-03-26: 1Active Exploitation · 2026-04-05: 1Patch / Workaround · 2026-03-10: 5Patch / Workaround · 2026-03-11: 14Patch / Workaround · 2026-03-12: 12Patch / Workaround · 2026-03-13: 4Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-16: 4Patch / Workaround · 2026-03-17: 3Patch / Workaround · 2026-03-19: 2Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-27: 2Patch / Workaround · 2026-03-29: 2Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-06-02: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-09-22: 1Technical Details · 2026-03-10: 4Technical Details · 2026-03-11: 19Technical Details · 2026-03-12: 9Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-17: 3Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 2Technical Details · 2026-03-29: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-14: 1Technical Details · 2026-05-10: 1Technical Details · 2026-06-02: 1Technical Details · 2026-06-16: 1Technical Details · 2026-09-22: 103-1003-1303-1703-2003-2604-0104-0504-1105-0506-1609-22
Signal classification5 categories
Patch
6270.5%
Disclosure
1213.6%
General
89.1%
Active Exploitation
55.7%
Disco
11.1%
Referenced assets57 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-107
Disclosure2Patch5
2026-03-1123
Active Exploitation4Disclosure5General2Patch12
2026-03-1214
Disclosure3Patch11
2026-03-135
General1Patch4
2026-03-142
General1Patch1
2026-03-164
Patch4
2026-03-174
Disclosure1Patch3
2026-03-181
Disclosure1
2026-03-192
Patch2
2026-03-202
Disco1Patch1
2026-03-231
Patch1
2026-03-241
Patch1
2026-03-263
Active Exploitation1General1Patch1
2026-03-272
Patch2
2026-03-292
Patch2
2026-04-011
Patch1
2026-04-031
Patch1
2026-04-041
General1
2026-04-051
Patch1
2026-04-091
General1
2026-04-101
Patch1
2026-04-111
Patch1
2026-04-141
Patch1
2026-04-221
Patch1
2026-05-051
Patch1
2026-05-101
Patch1
2026-06-021
Patch1
2026-06-161
General1
2026-06-231
Patch1
2026-09-221
Patch1
Full discourse20 posts
  • SoyITPro@SoyITPro
    Patch

    🔒 Updates – Marzo 2026 Microsoft corrige 84 fallos, incluyendo 8 críticos en Windows, Office, SQL Server, .NET y Azure: 🛑 CVE-2026-26127 (.NET) – Denegación de servicio por lectura fuera de límites. 📊 CVE-2026-21262 (SQL Server) – Escalada de privilegios hasta SQLAdmin. 📄 CVE-2026-26113 (Office) – RCE por puntero no confiable (CVSS 8.4) 📄 CVE-2026-26110 (Office) – RCE por confusión de tipos, explotable vía Panel de Vista Previa. 📊 CVE-2026-26144 (Excel) – Divulgación de información sensible en generación web. 🌐 CVE-2026-23654 (GitHub/PyPI) – RCE por dependencia maliciosa en paquetes de terceros. #Security #Windows #Updates

    Post summary

    Microsoft’s March 2026 update addresses 84 bugs, including 8 critical vulnerabilities across Windows, Office, SQL Server, .NET, and Azure, providing concise technical details for each CVE.

    0703131.3K
    12.3K followersView on X
  • Hunt.io@Huntio
    Disclosure

    🚩 Microsoft SQL Server Zero-Day Enables Privilege Escalation https://cybersecuritynews.com/microsoft-sql-server-zero-day-vulnerability/ Microsoft has disclosed a critical SQL Server zero-day (CVE-2026-21262) that lets authenticated users escalate privileges to sysadmin, the highest level in the database. The flaw affects SQL Server 2016 through 2025 and has already been publicly disclosed, increasing the risk of exploit development. With a CVSS score of 8.8, the flaw can be exploited over the network to gain full database control. Microsoft released patches and urges administrators to update immediately and review database permissions. #CyberSecurity #Microsoft #Vulnerability

    Post summary

    Microsoft has publicly disclosed CVE‑2026‑21262, a critical privilege‑escalation flaw in SQL Server, and released patches urging immediate administrators to update.

    0311131.2K
    5.1K followersView on X
  • インフォセキュアソリューションズ株式会社@InSecSol0417
    Patch

    🛠【Microsoft月例(2026年3月)】 IPAが注意喚起。 更新公開前に情報が出ていたCVE-2026-26127(.NET DoS)/CVE-2026-21262(SQL Server権限昇格)などを修正。 Windows Updateで更新確認→再起動まで実施を。 #企業公式相互フォロー

    Post summary

    The tweet announces that Microsoft’s March 2026 update includes fixes for CVE‑2026‑26127 (a .NET denial‑of‑service flaw) and CVE‑2026‑21262 (a SQL Server privilege escalation vulnerability), urging users to apply the update and reboot.

    000130263
    448 followersView on X
  • Emmanuel Nii Okai@engniiokai
    Patch

    ⚠️ PATCH NOW: Microsoft just fixed 83 vulnerabilities in the March 2026 Patch Tuesday update. Some highlights security teams should pay attention to: • CVE-2026-26144 – Excel flaw that can leak sensitive data through Copilot with zero user interaction • CVE-2026-26110 / CVE-2026-26113 – Microsoft Office RCE triggered just by previewing a malicious file • CVE-2026-21262 – SQL Server privilege escalation over network The real lesson: Attackers don’t always need malware anymore. Sometimes they just need: 📄 One document 👀 One preview pane 💥 One unpatched system Patch management isn’t boring it’s your first line of defense. #CyberSecurity #PatchTuesday #ThreatInte

    Post summary

    Microsoft released a March 2026 Patch Tuesday update fixing 83 vulnerabilities, including Office and SQL Server CVEs that enable data leakage, RCE, and privilege escalation, underscoring the necessity of timely patching.

    60010120
    808 followersView on X
  • ‘ALPAGU@alpagu995
    General

    CVE-2026-21262 Burdan ekmek çıkıyo

    Post summary

    The tweet references a CVE identifier but provides no additional technical context or actionable information.

    00061346
    164 followersView on X
  • White Rabbitx@TheRabbitPy
    General

    🛡️ MS ACI Containers crits: CVE-2026-23651/26124 (6.7 EoP). No wild exploits yet, but enterprise cloud alert! https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The message highlights Microsoft ACI Containers CVEs 2026-23651 and 2026-26124 with a 6.7 EoP severity, reports no wild exploits yet, and directs readers to a Tenable Blog about Patch Tuesday covering 83 CVEs.

    0003074
    438 followersView on X
  • SECUREU@secureu_in
    Patch

    And that's not all from March Patch Tuesday: - CVE-2026-26110: Office preview pane RCE, just viewing an email triggers the exploit - CVE-2026-21262: SQL Server zero-day, basic users escalate to full admin - 84 total vulnerabilities patched AI is Increasing your attack surface.

    Post summary

    The tweet announces that CVE‑2026‑26110 and CVE‑2026‑21262 were patched as part of March Patch Tuesday, describing them as an Office preview pane RCE and a SQL Server zero‑day, without providing exploit details or evidence of active attacks.

    1002074
    237 followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年3月ぱっちちゅーずーでー ▼Microsoft 2026 年 3 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/03/202603-security-update CVE-2026-26127 .NET のサービス拒否の脆弱性 CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ▼SAP SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html CVE-2019-17571 SAP Quotation Management Insurance アプリケーション (FS-QUO) におけるコードインジェクションの脆弱性 CVE-2026-27685 SAP NetWeaver Enterprise Portal 管理における安全でないデシリアライゼーション ▼Ivanti(critical系はなし) March 2026 Security Update https://www.ivanti.com/blog/march-2026-security-update CVE-2026-3483 バージョン 2026.1.1 より前の Ivanti DSM で公開されている危険な方法により、ローカルで認証された攻撃者が権限を昇格できる可能性 ▼Fortinet(critical系はなし) https://fortiguard.fortinet.com/psirt CVE-2026-22627 LLDP OUIフィールドのバッファオーバーフロー CVE-2025-54820 fgtupdates サービスによるバッファオーバーフロー ▼Adobe https://helpx.adobe.com/security.html

    Post summary

    The text provides an announcement of official security updates for several CVEs across Microsoft, SAP, Ivanti, Fortinet, and Adobe, including basic vulnerability descriptions but no PoC, exploit details, or active exploitation reports.

    100201.1K
    11.4K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    MS定例更新のTenable社解説。83件。緊急(Critical)が8件で75件が重要。 https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The post announces Microsoft’s March 2026 Patch Tuesday, noting 83 CVEs—including 8 critical—are being addressed, implying patch availability.

    00012599
    7.3K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🗄️ SQL Server priv-esc (CVE-2026-21262) Network-local EoP to DB admin (CVSS 8.8, publicly known). Exposed SQL = owned DB. Firewall + patch. https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127 #SQL #CVE

    Post summary

    CVE-2026-21262 is a non‑zero‑day privilege‑escalation flaw in SQL Server that can be mitigated via patching and firewall rules, with the Tenable blog offering the required updates.

    1001068
    492 followersView on X
  • Raed alroomi@master_roomi
    Disco

    ثغرات MS Office وSQL Server: تظل ثغرة (CVE-2026-26110) نشطة حيث تسمح باختراق الجهاز عبر لوحة المعاينة في Outlook دون فتح الملف. كما تم رصد ثغرة (CVE-2026-21262) في SQL Server تسمح برفع الصلاحيات لدرجة مدير نظام

    Post summary

    The post reports two Microsoft CVEs—CVE‑2026‑26110 and CVE‑2026‑21262—as still active, detailing how the first can be exploited via Outlook’s preview pane and the second grants sysadmin privileges in SQL Server, but offers no Proof‑of‑Concept, active exploitation evidence, or patch information.

    10010202
    12.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Microsoft SQL のゼロデイ CVE-2026-21262:最高管理者レベルへの権限昇格 https://iototsecnews.jp/2026/03/11/microsoft-sql-server-zero-day-vulnerability-allows-attackers-to-escalate-privileges/ Microsoft は 2026年3月10日の Patch Tuesday において、SQL Server に存在する深刻なゼロデイ脆弱性 CVE-2026-21262 (CVSS:8.8) が公開されました。この問題の原因は、SQL Server 内の不適切なアクセス制御 (CWE-284) にあります。この脆弱性は、低権限のユーザーであっても悪用が可能であり、ネットワーク経由でサーバにログインした後に、最高管理者権限である sysadmin に昇格する恐れがあります。 この脆弱性の最大のリスクは、情報の公開が先行しているゼロデイ状態である点です。攻撃の複雑性が低く、特別なユーザー操作も不要なため、一度データベースへのアクセスを許すと、情報の窃取や改竄/システムの破壊といった完全な制御を奪われる恐れがあります。特に、複数のユーザーが利用するマルチテナント環境や共有データベースを運用している組織は、内部不正や侵害されたアカウントからの攻撃に対して、きわめて脆弱な状態となります。 ご利用のチームは、ご注意ください。 #CVE202621262 #Microsoft #SQLServer #Vulnerability #ZeroDay

    Post summary

    Microsoft announced a critical zero‑day privilege escalation flaw in SQL Server (CVE‑2026‑21262) with identified CVSS score and CWE, but no PoC, exploit, or patch details are provided yet.

    02000183
    484 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🚨 Adobe Illustrator APSB26-18: Critical untrusted search path (CVSS 8.6) → DLL hijacking via .ai files + heap/stack overflows. Patch now! https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The tweet highlights a critical Adobe Illustrator flaw with DLL hijacking and memory overflows, urging users to apply the patch immediately.

    1001046
    350 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Disclosure

    🎙️ RadioCSIRT Ép.595 – Épisode Spécial du jeudi 12 mars 2026 Un seul sujet. Un cycle qui marque l'histoire des CVE : le Patch Tuesday Microsoft de mars 2026. 🔴 Microsoft Patch Tuesday – 79 vulnérabilités corrigées, deux zero-days publiquement divulgués. CVE-2026-26113 et CVE-2026-26110 : deux RCE critiques dans Microsoft Office déclenchables par simple visualisation d'un message dans le volet de prévisualisation, sans interaction utilisateur. 🔴 CVE-2026-26144 – Microsoft Excel et Copilot Agent Mode. Divulgation d'informations critique : un attaquant peut forcer Copilot à exfiltrer des données via un trafic réseau non prévu. Attaque zero-click documentée. 🔴 CVE-2026-21262 – SQL Server, élévation de privilèges jusqu'au niveau sysadmin via le réseau (CVSS 8.8). Zero-day publiquement divulgué avant correctif. CVE-2026-26127 – .NET, déni de service réseau sans authentification. 🔴 Six vulnérabilités Important signalées comme prioritaires par Cisco Talos et Tenable : Windows Graphics Component, Windows Kernel, Windows Accessibility Infrastructure, Windows SMB Server, Ancillary Function Driver for WinSock, Winlogon (découverte par Google Project Zero). 🔴 CVE-2026-21536 – CVSS 9.8 Critical. Première CVE officiellement attribuée à un agent IA autonome : XBOW, agent de penetration testing entièrement automatisé, sans accès au code source. Microsoft a corrigé côté serveur, sans action requise des utilisateurs. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-595-episode-special-patch-tuesday-microsoft-mars-2026/ 📖 Analyse complète sur le blog : https://blog.marcfredericgomez.fr/microsoft-patch-tuesday-mars-2026-79-vulnerabilites-corrigees-deux-zero-days-divulgues/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #PatchTuesday #Microsoft #CVE #ZeroDay #RCE #Windows #Office #SQLServer #Copilot #AI #XBOW #PatchManagement #VulnerabilityManagement #InfoSec #CERT #CSIRT #SOC #CISO #VOC #Patch

    Post summary

    The post announces Microsoft Patch Tuesday 2026, detailing 79 vulnerabilities—including two zero-days with documented exploitation—and notes that Microsoft has patched them server‑side with no user action required.

    0002060
    413 followersView on X
  • VulnDex@VulnDex
    Disclosure

    🔎 Trending CVE Erhöhte Berichterstattung zu CVE-2026-21262 in Microsoft SQL Server. Ein authentifizierter Angreifer mit niedrigen Rechten kann seine Privilegien auf sysadmin-Level erhöhen. Aktive Ausnutzung ist noch nicht bekannt. https://vulndex.at/cve/CVE-2026-21262 https://t.co/HpSEULZlqW

    Post summary

    The tweet notes increased reporting on CVE‑2026‑21262, outlining a privilege‑elevation flaw in Microsoft SQL Server, but does not indicate active exploitation, a PoC, or a patch.

    0101047
    1 followersView on X
  • NEWSTECNICAS | Tecnología, IA y Gaming.@newstecnicas
    Patch

    #Microsoft corrige Zero-Day crítico en #SQLServer que permite a atacantes tomar el control total como admin | CVE-2026-21262 https://www.newstecnicas.info.ve/2026/03/microsoft-parche-marzo-zero-day-sql-server-cve-2026-21262.html

    Post summary

    The text announces Microsoft has applied a patch to fix a critical zero‑day in SQL Server that could allow attackers to gain full administrative control.

    0100075
    1.2K followersView on X
  • ChangeWatch@changewatchdev
    Patch

    RDS Custom adds Microsoft GDR fixes for SQL Server 2019 & 2022 If you run Amazon RDS Custom for SQL Server, you can now apply Microsoft GDR security updates that remediate CVE-2026-21262 and CVE-2026-26115 — you should plan to patch… Read more → http://changewatch.dev/explore/3b43dcc1-3c02-4574-b356-e8c5561d2405

    Post summary

    Amazon RDS Custom now includes Microsoft GDR security updates that fix CVE-2026-21262 and CVE-2026-26115 for SQL Server 2019 & 2022, and users should plan to apply the patches.

    0001046
    3 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    📊 CVE-2026-21262 (Microsoft SQL Server): 8.8 EoP to sysadmin publicly disclosed. Patch: March 2026 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21262 https://nvd.nist.gov/vuln/detail/CVE-2026-21262 https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    Microsoft SQL Server CVE-2026-21262 is an Elevation of Privilege vulnerability with a CVSS score of 8.8; a patch was released in March 2026 and is referenced by Microsoft and NVD links.

    1000052
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Active Exploitation

    ⚡ CVE-2026-21262 (Win32k EoP, CVSS 9.8): Actively exploited zero-day from Mar Patch Tuesday. Elevates privileges on Windows endpoints. Deploy patches! https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21262

    Post summary

    CVE-2026-21262 is a Win32k privilege escalation bug actively exploited in the wild; Microsoft has issued patches and recommends deployment.

    1000077
    492 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21262 Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-21262

    Post summary

    The text announces a new privilege‑escalation vulnerability in SQL Server (CVE‑2026‑21262) with a brief technical description and a link to the CVE record.

    00010161
    56.8K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsql_server_2016--x64
Appmicrosoftsql_server_2017--x64
Appmicrosoftsql_server_2019--x64
Appmicrosoftsql_server_2022--x64
Appmicrosoftsql_server_2025--x64

Explore more