CVE-2026-33120Disclosure(microsoft / sql_server_2016)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft sql_server_2016 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sql_server_2016
  • sql_server_2017
  • sql_server_2019
  • sql_server_2022

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-15)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
sql_server_2016sql_server_2017sql_server_2019sql_server_2022sql_server_2025

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 204-1404-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-152
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33120 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-33120

    Post summary

    The CVE-2026-33120 vulnerability is announced as a remote code execution flaw in SQL Server via an untrusted pointer dereference; no PoC, exploit, active exploitation, or patch details are included.

    000111.5K
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33120 Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-33120 ----- Traducción: CVE-2026-33120 Desreferenciación de puntero no confiable en SQL Server permite a … http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-33120) is announced, describing an untrusted pointer dereference in SQL Server that permits remote code execution by authorized attackers.

    0000036
    71 followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-33120 | Microsoft SQL Server 2022 (GDR) | Remote Code Execution Description Untrusted pointer dereference in Microsoft SQL Server 2022 (GDR) allows an auth'd attacker to achieve RCE over a network by triggering invalid memory access. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Microsoft SQL Server 2022 (GDR) Affected Version: >= 16.0.0 and < 16.0.1175.1 Sources Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33120

    Post summary

    CVE‑2026‑33120 is a high‑severity RCE vulnerability in Microsoft SQL Server 2022 (GDR), with a patch now available and no evidence of active exploitation.

    0000040
    8 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsql_server_2016--x64
Appmicrosoftsql_server_2017--x64
Appmicrosoftsql_server_2019--x64
Appmicrosoftsql_server_2022--x64
Appmicrosoftsql_server_2025--x64

Explore more