Microsoft Security Response Center Follow CVE-2026-66819 Microsoft SQL Server Elevation of Privilege Vulnerability Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66819 msrc.microsoft.com