Our automated tracking framework flagged that CISA added CVE-2019-1068 (Microsoft SQL Server) to the Known Exploited Vulnerabilities (KEV) catalog on August 28, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2019-1068 by August 29, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2019-1068
Vendor / product Microsoft SQL Server
Vulnerability Microsoft SQL Server Remote Code Execution Vulnerability
CVSS base score 8.8
Added to KEV August 26, 2026
Days public before listing (NVD → KEV lag) 2599
Federal patch deadline August 29, 2026
Known ransomware use No

How This Compares to Microsoft’s Track Record

This one was public for 2599 days before CISA confirmed exploitation — longer than Microsoft’s 564-day median, a vulnerability that sat exploitable in the open. Microsoft currently ranks #18 on our KEV Lag leaderboard.

Microsoft in the CISA KEV catalog Value
Tracked KEV entries 386
Median lag (public → KEV listing) 564 days
0-day rate (exploited at or before disclosure) 23%
Entries tied to known ransomware campaigns 104

For perspective, the median across all 1684 tracked KEV entries is 267 days — Microsoft’s exploited vulnerabilities are flagged slower than the catalog average.

Other Recent Microsoft KEV Additions

The most recent Microsoft vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2026-33824 Internet Key Exchange (IKE) Service Extensions August 18, 2026 126 No
CVE-2026-55040 SharePoint August 18, 2026 35 No
CVE-2026-68820 Windows Ancillary Function Driver for WinSock August 11, 2026 0 No
CVE-2026-50522 SharePoint July 22, 2026 8 No
CVE-2026-58644 SharePoint July 16, 2026 2 No

What This Means for Defenders

CISA has added CVE-2019-1068, a Microsoft SQL Server Remote Code Execution vulnerability (CVSS 8.8), to its Known Exploited Vulnerabilities Catalog. The federal patch deadline for this vulnerability is August 29, 2026. This vulnerability was public for 2599 days before its KEV listing. Patching Microsoft SQL Server instances is a high priority, especially for systems exposed to the internet or accessible from less trusted networks.

CVE-2019-1068’s proven exploitation shows that threat actors are actively leveraging it. There’s no known ransomware use currently associated with this CVE. This extended period of potential exploitation makes thorough review and patching necessary.

If you can’t patch before the August 29 deadline, restrict network access to SQL Server instances to only necessary services and hosts, apply strong firewall rules, segment networks, and monitor for anomalous activity. Regular backups and a tested incident response plan are also important to mitigate potential impact while a permanent patch is prepared and deployed.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.