Your Forgotten SQL Server Just Landed on CISA’s Emergency List

CISA has added a seven-year-old Microsoft SQL Server vulnerability to its exploited list, turning forgotten database instances into an urgent incident-response problem.

CISA has added a seven-year-old Microsoft SQL Server vulnerability to its exploited list, turning forgotten database instances into an urgent incident-response problem.

Microsoft says a China-focused campaign is rebuilding malicious installers between downloads, making familiar names and file hashes unreliable clues.

A fake verification prompt led to DLL sideloading, Active Directory reconnaissance and a reverse tunnel that turned one Windows endpoint into an internal network pivot.

KB5120998 may reset cursor styling, wallpaper and text rendering on some Windows 11 PCs. This Dutch and English guide explains when and how to remove the optional update safely.

Microsoft labels KB5120998 a non-security preview, but it changes administrator protection, AI process isolation, WMIC availability, post-quantum TLS and enterprise deployment behaviour.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

Update, 22 August 2026: Microsoft has told BleepingComputer that it mistakenly marked a maximum-severity Microsoft Entra ID vulnerability as exploited in the wild. The correction removes the strongest public claim behind the first version of this article. It does not…

ExfilSquad’s leaked data points to exposed Dataverse records, not a confirmed Dynamics exploit. Anonymous low-code permissions can be the entire breach path.

Microsoft will retire its Entra SMS and voice authentication service in February 2027, making passkey migration and exception governance urgent.

Fix the Caesar IV runtime error on Windows 10 with legacy DirectX components, DLL registration and compatibility settings, with careful Windows 11 guidance.