LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 12, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-43468 to its Known Exploited Vulnerabilities catalog on Feb 12, 2026, with a federal patch deadline of Mar 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment…

Microsoft Configuration Manager contains an SQL injection vulnerability tracked as CVE-2024-43468. An unauthenticated attacker can send specially crafted requests that the product processes in an unsafe manner, allowing execution of commands on the server or its underlying database. The issue matters because Configuration Manager often holds broad administrative control over enterprise devices and data stores.

How it works

The weakness is categorized as CWE-89, an improper neutralization of special elements used in an SQL command. An attacker supplies input that is concatenated into SQL statements without adequate sanitization or parameterization. When the application executes the resulting query, the injected syntax alters the intended command, enabling the attacker to read, modify, or control data and potentially issue operating-system commands through database features.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor-supplied update referenced in the Microsoft security advisory. After patching, confirm that the affected components have been restarted and that any required post-installation steps have been completed. Review Configuration Manager’s database access controls and ensure service accounts follow the principle of least privilege.

If you can't patch immediately

If your data may have been exposed

SQL injection flaws that permit unauthenticated command execution have been used to obtain persistent access and exfiltrate data. Organizations can run a free exposure scan of their domains and email addresses against known breach datasets to determine whether related credentials or records already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Configuration Manager
WeaknessCWE-89
Added to CISA KEVFeb 12, 2026
Federal patch deadlineMar 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities