That SQL Box Under the Desk Just Hit CISA’s Exploited List
Microsoft 365 does not patch the SQL Server under the desk.
On August 26, 2026, CISA added CVE-2019-1068 to its Known Exploited Vulnerabilities catalog. The entry is for Microsoft SQL Server remote code execution. The federal due date on that listing is August 29, 2026. That is today if you are reading this as a Saturday catch-up post, and it is already the point for any Staten Island or outer-borough practice that still runs SQL Server 2014, 2016, or 2017 for a line-of-business app.
We already wrote about the leftover Exchange box. This is the database version of that problem. Different product. Same habit: the firm moved mail to the cloud and left one machine that “just runs the practice software.”
What CISA actually listed
CISA’s August 26 alert says six vulnerabilities were added to the KEV catalog based on evidence of active exploitation. CVE-2019-1068 is one of them. The KEV description is short: Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CISA marks ransomware use for this CVE as Unknown. We are not going to upgrade that into a claim. Forensic triage required under BOD 26-04 is Yes for this entry. Date added is August 26, 2026. Due date is August 29, 2026.
Binding Operational Directive 26-04 binds Federal Civilian Executive Branch agencies. It does not put a private NYC dental office under a federal clock. CISA still tells every organization to treat the KEV catalog as a prioritization input. That is the useful line for a 15-user firm: when CISA says a bug is exploited, stop treating it as a routine Patch Tuesday item.
The same August 26 drop also includes Citrix NetScaler CVE-2026-8452 with the same federal due date. If you do not run NetScaler, ignore that sentence and stay on SQL.
What the bug is, without the exploit cookbook
NVD published CVE-2019-1068 on July 15, 2019. The description is that a remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions. NVD’s last modified date on the record we checked moved to August 27, around the KEV listing.
NVD scores it CVSS 3.1 base 8.8 High. The affected product lines listed for this CVE include SQL Server 2014 (SP2 and SP3 branches), SQL Server 2016 (SP1 and SP2), and SQL Server 2017. We are not going to invent CU numbers or pretend SQL Server 2019 and 2022 are in that list.
High level: an attacker who can reach a vulnerable instance and send a crafted query may run code as the database engine service account. That is enough for a weekend inventory. It is not a license to paste PoC queries into a blog.
Microsoft’s advisory is the remediation path CISA points to: CVE-2019-1068.
Why a 15-user NYC firm still has this box
A lot of practices did not “choose” SQL Server. The practice management, imaging, or accounting package installed it. The install happened in 2016. The vendor support contract lapsed. Nobody RDP’d to that machine unless the app broke. Port 1433 may still be reachable from the whole office VLAN, or worse, from a VPN that every contractor shares.
If the app vendor says “we only support SQL Server 2016,” that is not a reason to stay unpatched. It is a reason to schedule the upgrade conversation and still apply the security update Microsoft published for that branch. Unsupported and unpatched are two different failures. This weekend you can fix the second one.
That is not a data-center story. It is a closet or a mini-tower under the front desk with a blue light that has been on for years.
SHIELD still cares whether you can name your systems and patch the ones that process private information. We already walked the SHIELD checklist. A SQL instance that holds patient, client, or payroll data is on that list whether or not BOD 26-04 applies to you.
How fast exploited bugs become a business problem is the same pressure we covered on zero-day velocity. KEV is CISA saying the exploitation evidence is already there.
Seven things a 15-user shop can finish this weekend
- Find every SQL Server instance. One person who knows the practice app writes down every machine that hosts a database: hostname, version, and whether it is 2014, 2016, 2017, or newer. If nobody can name the machine, that is the finding.
- Check the KEV versions first. If you are on SQL Server 2014, 2016, or 2017, treat CVE-2019-1068 as in-scope until the Microsoft update for that branch is confirmed installed. If you are only on 2019 or later for this CVE’s listed lines, say that in writing. Do not guess.
- Open Microsoft’s advisory and match your branch. Use the MSRC page CISA links. Install the security update for your GDR or CU path. Reboot if the package requires it. Confirm the build number after.
- If you cannot patch tonight, shrink the blast radius. Block 1433 and SQL Browser from anything that is not the app server. Kill guest or leftover SQL logins. Turn off public internet exposure if it exists. That is a weekend control, not a substitute for the update.
- Look at the service account. The KEV text is about code running as the Database Engine service account. If that account is a domain admin, you have two problems. Document what it is. Plan to reduce it after you patch.
- Decide whether the app still needs on-prem SQL. Some vendors have a cloud or newer SQL path. Some do not. Get the answer in one email. “We’ve always had that box” is not an architecture.
- Backups are still not optional. Patching a compromised host is not the same as restoring clean data. If the practice app’s database is only on that tower, make sure you have a tested copy that is not sitting next to the same malware path. We already covered why tenant retention is not a backup; the same rule applies to the SQL files under the desk.
Identity and email still decide how attackers get a foothold. This post is whether the database host they land on is still a 2017-era SQL build with a seven-year-old CVE that CISA just elevated.
How MicroSky helps — on this instance, not a generic stack
We will tell you, in writing:
- Which machines in the office are actually running SQL Server, and which version.
- Whether CVE-2019-1068’s listed branches apply to those builds.
- Whether the Microsoft security update for that branch is installed.
- Whether SQL is reachable from more of the network than the app needs.
- What the SQL service account is, and whether it is over-privileged.
We will not replace that inventory with a slide about “legacy tech debt.”
Call MicroSky at (718) 672-2177 or visit microskyms.com for a free, no-obligation look at that leftover SQL box. We serve NYC, Staten Island, New Jersey, and the tri-state.
Ask which version it is, when it was last patched, and who can log into it from the office Wi-Fi. If nobody can answer in one minute, that is the finding.

