SQL Server security

SQL Server vulnerabilities

Search Microsoft SQL Server CVEs, affected releases, servicing branches, security-update builds, KB articles, and MSRC exploitation status. Open a record to find the CU, GDR, or service-pack update path that matches your server.

Every vulnerability record on this page comes from Microsoft Security Response Center. MSRC supplies the CVE details, revision history, affected update paths, builds after update, and security-update links.

After you identify the applicable security update, use the SQL Server updates list to verify its place in the CU or GDR history and the SQL Server patching guide to plan the change.

Catalog summary

SQL Server vulnerability counts

These counts summarize the current MSRC catalog by severity, release date, and public disclosure. Open the CVE list to check an individual record against your SQL Server product, servicing path, and installed build.

Critical severity

2

Rated by Microsoft

Released in 2025 or 2026

34

Recent Microsoft records

Publicly disclosed

5

Marked public by Microsoft

SQL Server CVE list

Latest SQL Server vulnerabilities and CVEs

Newest Microsoft revisions appear first. Search by CVE, SQL Server release, servicing branch, update build, KB article, severity, or impact. Open a result to see Microsoft update paths, builds after update, revision notes, and the original record.

Microsoft places Reporting Services and some related data products in the SQL Server product family. Confirm the exact affected-product row before choosing an update.

Showing 18 of 253 matching records

CVE-2026-55002 - Microsoft SQL Server elevation of privilege vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 GDR / CU6 · 2022 CU25 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 7.8Elevation of Privilege

External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3540.1KB 5102337Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2120.1KB 5102338Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7095.1KB 5102339Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6500.1KB 5102340Download
Microsoft SQL Server 2022 for x64-based Systems (CU 25)16.0.4262.2KB 5101347Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1190.2KB 5102334Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4480.2KB 5102335Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2180.2KB 5102336Download

CVE-2026-54118 - Microsoft SQL Server remote code execution vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 CU6 / GDR · 2022 CU25 / GDR · 2019 CU32 / GDR · 2017 GDR / CU31 · 2016 SP3 GDR / SP3 Azure Connect
CriticalCVSS 8.8Remote Code Execution

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2120.1KB 5102338Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6500.1KB 5102340Download
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download
Microsoft SQL Server 2022 for x64-based Systems (CU 25)16.0.4262.2KB 5101347Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4480.2KB 5102335Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3540.1KB 5102337Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1190.2KB 5102334Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2180.2KB 5102336Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7095.1KB 5102339Download

CVE-2026-54117 - Microsoft SQL Server remote code execution vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 CU6 / GDR
CriticalCVSS 8.8Remote Code Execution

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download

CVE-2026-54116 - Microsoft SQL Server information disclosure vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 CU6 / GDR
ImportantCVSS 6.5Information Disclosure

Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download

CVE-2026-50468 - Microsoft SQL Server information disclosure vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 GDR / CU6
ImportantCVSS 6.5Information Disclosure

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download

CVE-2026-47296 - Microsoft SQL Server elevation of privilege vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 GDR / CU6 · 2022 GDR / CU25 · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 7.8Elevation of Privilege

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4480.2KB 5102335Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1190.2KB 5102334Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3540.1KB 5102337Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7095.1KB 5102339Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6500.1KB 5102340Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2180.2KB 5102336Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2120.1KB 5102338Download
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download
Microsoft SQL Server 2022 for x64-based Systems (CU 25)16.0.4262.2KB 5101347Download

CVE-2026-47295 - Microsoft SQL Server elevation of privilege vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches 2025 CU6 / GDR · 2022 CU25 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 8.8Elevation of Privilege

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU6)17.0.4060.2KB 5101346Download
Microsoft SQL Server 2022 for x64-based Systems (CU 25)16.0.4262.2KB 5101347Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4480.2KB 5102335Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1125.2KB 5102333Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1190.2KB 5102334Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3540.1KB 5102337Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7095.1KB 5102339Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6500.1KB 5102340Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2180.2KB 5102336Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2120.1KB 5102338Download

CVE-2026-42990 - SQL Server ODBC driver elevation of privilege vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches See the Microsoft advisory
ImportantCVSS 9.8Remote Code Execution

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Microsoft lists this CVE under SQL Server, but the affected-product table is unavailable.

CVE-2026-58647 - Microsoft PowerBI Report Server spoofing vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches Power BI Report Server
Related SQL product
ImportantCVSS 8.0Spoofing

Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Power BI Report Server15.0.1121.120KB Release NotesDownload

CVE-2026-56642 - Microsoft Fabric Data Warehouse remote code execution vulnerability

Released 14 Jul 2026Revised 14 Jul 2026Open detailsAffected branches Fabric Data Warehouse
Related SQL product
ImportantCVSS 8.8Remote Code Execution

Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Fabric Data Warehouse8.0.206.113KB Release NotesDownload

CVE-2026-40370 - SQL Server remote code execution vulnerability

Released 12 May 2026Revised 12 May 2026Open detailsAffected branches 2025 GDR / CU4 · 2022 GDR / CU24 · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 8.8Remote Code Execution

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4470.1KB 5090407Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1115.1KB 5091223Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1180.1KB 5091158Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3530.2KB 5090354Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7085.1KB 5089270Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6490.1KB 5089271Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2170.1KB 5090408Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2110.2KB 5090347Download
Microsoft SQL Server 2022 for x64-based Systems (CU 24)16.0.4252.3KB 5089900Download
Microsoft SQL Server 2025 for x64-based Systems (CU4)17.0.4040.1KB 5089899Download

CVE-2026-33120 - Microsoft SQL Server remote code execution vulnerability

Released 14 Apr 2026Revised 14 Apr 2026Open detailsAffected branches 2022 GDR
ImportantCVSS 8.8Remote Code Execution

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1175.1KB 5084815Download

CVE-2026-32176 - SQL Server elevation of privilege vulnerability

Released 14 Apr 2026Revised 14 Apr 2026Open detailsAffected branches 2025 GDR / CU3 · 2022 GDR / CU24 · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 6.7Elevation of Privilege

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4465.1KB 5084816Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1175.1KB 5084815Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3525.1KB 5084818Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7080.1KB 5084820Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6485.1KB 5084821Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2165.1KB 5084817Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2105.1KB 5084819Download
Microsoft SQL Server 2022 for x64-based Systems (CU 24)16.0.4250.1KB 5083252Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1110.1KB 5084814Download
Microsoft SQL Server 2025 for x64-based Systems (CU3)17.0.4030.1KB 5083245Download

CVE-2026-32167 - SQL Server elevation of privilege vulnerability

Released 14 Apr 2026Revised 14 Apr 2026Open detailsAffected branches 2025 CU3 / GDR · 2022 CU24 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 6.7Elevation of Privilege

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (CU 24)16.0.4250.1KB 5083252Download
Microsoft SQL Server 2025 for x64-based Systems (CU3)17.0.4030.1KB 5083245Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4465.1KB 5084816Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1110.1KB 5084814Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3525.1KB 5084818Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1175.1KB 5084815Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7080.1KB 5084820Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6485.1KB 5084821Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2105.1KB 5084819Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2165.1KB 5084817Download

CVE-2026-26133 - M365 Copilot information disclosure vulnerability

Released 12 Mar 2026Revised 9 Apr 2026Open detailsAffected branches PowerBI for iOS · PowerBI for Android
Related SQL product
ImportantCVSS 7.1Information Disclosure

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Microsoft revision

Version 1.2. Updated CWE value. This is an informational change only.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft PowerBI for iOS1.2.260302.2193910KB Release NoteDownload
Microsoft PowerBI for Android2.2.260210.21290750KB Release NoteDownload

CVE-2026-26116 - SQL Server elevation of privilege vulnerability

Released 10 Mar 2026Revised 10 Mar 2026Open detailsAffected branches 2025 CU2 / GDR
ImportantCVSS 8.8Elevation of Privilege

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU2)17.0.4020.2KB 5077466Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1105.2KB 5077468Download

CVE-2026-26115 - SQL Server elevation of privilege vulnerability

Released 10 Mar 2026Revised 10 Mar 2026Open detailsAffected branches 2025 CU2 / GDR · 2022 CU23 / GDR · 2019 GDR / CU32 · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
ImportantCVSS 8.8Elevation of Privilege

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7075.5KB 5077473Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2160.4KB 5077470Download
Microsoft SQL Server 2025 for x64-based Systems (CU2)17.0.4020.2KB 5077466Download
Microsoft SQL Server 2022 for x64-based Systems (CU 23)16.0.4240.4KB 5077464Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4460.4KB 5077469Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1170.5KB 5077465Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3520.4KB 5077471Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6480.4KB 5077474Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2100.4KB 5077472Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1105.2KB 5077468Download

CVE-2026-21262 - SQL Server elevation of privilege vulnerability

Released 10 Mar 2026Revised 10 Mar 2026Open detailsAffected branches 2025 CU2 / GDR · 2022 CU23 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR · 2016 SP3 Azure Connect / SP3 GDR
Public
ImportantCVSS 8.8Elevation of Privilege

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU2)17.0.4020.2KB 5077466Download
Microsoft SQL Server 2022 for x64-based Systems (CU 23)16.0.4240.4KB 5077464Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4460.4KB 5077469Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1105.2KB 5077468Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1170.5KB 5077465Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack13.0.7075.5KB 5077473Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3520.4KB 5077471Download
Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)13.0.6480.4KB 5077474Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2160.4KB 5077470Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2100.4KB 5077472Download

Check your server

Check whether a SQL Server CVE affects your build

Start with the installed build. Product names such as SQL Server 2022 are too broad because Microsoft ships separate fixes for different servicing branches.

Get the installed version

Run this read-only query on each SQL Server instance. Availability Group replicas and cluster nodes can have different builds during maintenance.

SELECT
  SERVERPROPERTY('ProductVersion')
    AS ProductVersion,
  SERVERPROPERTY('ProductLevel')
    AS ProductLevel,
  SERVERPROPERTY('Edition')
    AS Edition;
  1. Identify the servicing path

    Open the CVE and find the CU, GDR, service-pack, or feature-pack row that matches the installed SQL Server release.

  2. Check the KB prerequisites

    The MSRC base product version is not an affected-build boundary. Use the linked KB to confirm which earlier builds can take that update.

  3. Verify the resulting build

    After patching, confirm that ProductVersion matches or exceeds the build published by Microsoft for the selected update path.

Treat an exploited CVE as urgent. You still need the correct CU or GDR, a backup and rollback plan, and a tested validation check. Continue with the SQL Server updates list and patching guide.

Data source

Microsoft Security Response Center

The Microsoft Security Response Center (MSRC) publishes Microsoft's vulnerability advisories and Security Update Guide. It records which products are affected and which security updates address them.

This tracker reads its CVEs, revisions, severity ratings, affected update paths, builds, exploitation flags, and KB links from MSRC. Open the Microsoft record before patching because affected products and guidance can change after publication.

Open the MSRC Security Update Guide

Microsoft CVE details, revision history, severity, affected update paths, security-update builds, and KB links.

Status

Checked

Records

253 CVEs

SQL Server vulnerability FAQ

Where should I check for SQL Server vulnerabilities?

+

Microsoft Security Response Center is the source for this SQL Server CVE tracker. Its records provide revision history, severity, affected update paths, builds installed by each security update, exploitation status, and Knowledge Base links.

How do I know whether a CVE affects my SQL Server build?

+

Get the ProductVersion, ProductLevel, and edition from the server. Identify its CU, GDR, or service-pack path, then open the matching Microsoft KB and check the prerequisites. A release year or MSRC base product version alone is too broad to confirm exposure.

What does Microsoft: exploited mean?

+

It means MSRC marks the vulnerability as exploited. Treat it as a prioritization flag, then confirm the affected product, build, attack conditions, and applicable Microsoft security update.

Does a critical CVSS score mean my SQL Server is vulnerable?

+

No. CVSS describes technical severity. Exposure depends on the affected SQL Server product, installed build, configuration, access path, and the conditions described in the Microsoft advisory.

How current is this SQL Server CVE list?

+

The Last checked date shows when MSRC was most recently read. Newest Microsoft revisions appear first. Open the Microsoft record before patching because affected products, FAQs, and update guidance can change after publication.