Microsoft Azure Sql Database — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Azure Sql Database, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2026-56162 — CVSS 10.0 (critical): Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69502 — CVSS 10.0 (critical): Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-68782 — CVSS 9.9 (critical): Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to…
CVE-2026-68789 — CVSS 9.9 (critical): Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to…
CVE-2026-66309 — CVSS 9.1 (critical): Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-63522 — CVSS 7.8 (high): Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.