Our automated tracking framework flagged that CISA added CVE-2019-1068 (Microsoft SQL Server) to the Known Exploited Vulnerabilities (KEV) catalog on August 28, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2019-1068 by August 29, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2019-1068 |
| Vendor / product | Microsoft SQL Server |
| Vulnerability | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVSS base score | 8.8 |
| Added to KEV | August 26, 2026 |
| Days public before listing (NVD → KEV lag) | 2599 |
| Federal patch deadline | August 29, 2026 |
| Known ransomware use | No |
How This Compares to Microsoft’s Track Record
This one was public for 2599 days before CISA confirmed exploitation — longer than Microsoft’s 564-day median, a vulnerability that sat exploitable in the open. Microsoft currently ranks #18 on our KEV Lag leaderboard.
| Microsoft in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 386 |
| Median lag (public → KEV listing) | 564 days |
| 0-day rate (exploited at or before disclosure) | 23% |
| Entries tied to known ransomware campaigns | 104 |
For perspective, the median across all 1684 tracked KEV entries is 267 days — Microsoft’s exploited vulnerabilities are flagged slower than the catalog average.
Other Recent Microsoft KEV Additions
The most recent Microsoft vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-33824 | Internet Key Exchange (IKE) Service Extensions | August 18, 2026 | 126 | No |
| CVE-2026-55040 | SharePoint | August 18, 2026 | 35 | No |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | August 11, 2026 | 0 | No |
| CVE-2026-50522 | SharePoint | July 22, 2026 | 8 | No |
| CVE-2026-58644 | SharePoint | July 16, 2026 | 2 | No |
What This Means for Defenders
CISA has added CVE-2019-1068, a Microsoft SQL Server Remote Code Execution vulnerability (CVSS 8.8), to its Known Exploited Vulnerabilities Catalog. The federal patch deadline for this vulnerability is August 29, 2026. This vulnerability was public for 2599 days before its KEV listing. Patching Microsoft SQL Server instances is a high priority, especially for systems exposed to the internet or accessible from less trusted networks.
CVE-2019-1068’s proven exploitation shows that threat actors are actively leveraging it. There’s no known ransomware use currently associated with this CVE. This extended period of potential exploitation makes thorough review and patching necessary.
If you can’t patch before the August 29 deadline, restrict network access to SQL Server instances to only necessary services and hosts, apply strong firewall rules, segment networks, and monitor for anomalous activity. Regular backups and a tested incident response plan are also important to mitigate potential impact while a permanent patch is prepared and deployed.
Related Coverage
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
- Microsoft’s CVE-2026-68820 Was Exploited in 0 Days — Well Under Its 567-Day Median (August 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.