SQL Server security

SQL Server vulnerabilities

Search Microsoft SQL Server CVEs, affected releases, servicing branches, security-update builds, KB articles, and MSRC exploitation status. Open a record to find the CU, GDR, or service-pack update path that matches your server.

Every vulnerability record on this page comes from Microsoft Security Response Center. MSRC supplies the CVE details, revision history, affected update paths, builds after update, and security-update links.

After you identify the applicable security update, use the SQL Server updates list to verify its place in the CU or GDR history and the SQL Server patching guide to plan the change.

Catalog summary

SQL Server vulnerability counts

These counts summarize the current MSRC catalog by severity, release date, and public disclosure. Open the CVE list to check an individual record against your SQL Server product, servicing path, and installed build.

Critical severity

7

Rated by Microsoft

Released in 2025 or 2026

99

Recent Microsoft records

Publicly disclosed

5

Marked public by Microsoft

SQL Server CVE list

Latest SQL Server vulnerabilities and CVEs

Newest Microsoft revisions appear first. Search by CVE, SQL Server release, servicing branch, update build, KB article, severity, or impact. Open a result to see Microsoft update paths, builds after update, revision notes, and the original record.

Microsoft places Reporting Services and some related data products in the SQL Server product family. Confirm the exact affected-product row before choosing an update.

Showing 18 of 318 matching records

CVE-2026-78456 - SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2022 GDR / CU26
ImportantCVSS 8.8Remote Code Execution

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download

CVE-2026-77488 - Microsoft SQL Server information disclosure vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 GDR / CU26 · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 5.5Information Disclosure

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download

CVE-2026-77487 - SQL Server elevation of privilege vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 GDR / CU8 · 2022 CU26 / GDR · 2019 GDR / CU32 · 2017 CU31 / GDR
ImportantCVSS 8.8Elevation of Privilege

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-77486 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 8.8Remote Code Execution

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-77485 - SQL Server elevation of privilege vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 7.0Elevation of Privilege

Use after free in SQL Server allows an authorized attacker to elevate privileges locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-77484 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR
ImportantCVSS 8.8Remote Code Execution

Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download

CVE-2026-77483 - SQL Server elevation of privilege vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 8.8Elevation of Privilege

Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download

CVE-2026-77482 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 8.8Remote Code Execution

Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-77481 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 GDR / CU8 · 2022 GDR / CU26 · 2019 GDR / CU32 · 2017 GDR / CU31
ImportantCVSS 8.8Remote Code Execution

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download

CVE-2026-77480 - SQL Server elevation of privilege vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 8.8Elevation of Privilege

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-73029 - Microsoft SQL Server information disclosure vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR
ImportantCVSS 6.5Information Disclosure

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download

CVE-2026-73028 - SQL Server elevation of privilege vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 GDR / CU8 · 2022 GDR / CU26 · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 8.8Elevation of Privilege

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download

CVE-2026-69562 - Microsoft SQL Server information disclosure vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 6.5Information Disclosure

Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-68787 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 7.8Remote Code Execution

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-68786 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 GDR / CU8 · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 8.8Remote Code Execution

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-68785 - Microsoft SQL Server remote code execution vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 4.9Remote Code Execution

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

CVE-2026-68784 - Microsoft SQL Server information disclosure vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 CU32 / GDR · 2017 CU31 / GDR
ImportantCVSS 6.5Information Disclosure

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download

CVE-2026-68781 - Microsoft SQL Server information disclosure vulnerability

Released 8 Sept 2026Revised 8 Sept 2026Open detailsAffected branches 2025 CU8 / GDR · 2022 CU26 / GDR · 2019 GDR / CU32 · 2017 CU31 / GDR
ImportantCVSS 6.5Information Disclosure

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

Microsoft revision

Version 1. Information published.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Open the Microsoft record

Affected releases and Microsoft updates

MSRC lists separate security updates for CU, GDR, and service-pack paths. The build after update is the version installed by that KB package. Open the KB to confirm its prerequisites for your current build.

Release / update pathBuild after updateSecurity update
Microsoft SQL Server 2019 for x64-based Systems (GDR)15.0.2190.7KB 5122773Download
Microsoft SQL Server 2025 for x64-based Systems (CU8)17.0.4085.5KB 5122769Download
Microsoft SQL Server 2022 for x64-based Systems (CU 26)16.0.4275.2KB 5122768Download
Microsoft SQL Server 2019 for x64-based Systems (CU 32)15.0.4490.9KB 5122772Download
Microsoft SQL Server 2025 for x64-based Systems (GDR)17.0.1135.8KB 5122770Download
Microsoft SQL Server 2022 for x64-based Systems (GDR)16.0.1200.5KB 5122771Download
Microsoft SQL Server 2017 for x64-based Systems (CU 31)14.0.3550.4KB 5122774Download
Microsoft SQL Server 2017 for x64-based Systems (GDR)14.0.2130.4KB 5122775Download

Check your server

Check whether a SQL Server CVE affects your build

Start with the installed build. Product names such as SQL Server 2022 are too broad because Microsoft ships separate fixes for different servicing branches.

Get the installed version

Run this read-only query on each SQL Server instance. Availability Group replicas and cluster nodes can have different builds during maintenance.

SQL

Get the installed SQL Server version

T-SQL · 7 lines

SELECT  SERVERPROPERTY('ProductVersion')    AS ProductVersion,  SERVERPROPERTY('ProductLevel')    AS ProductLevel,  SERVERPROPERTY('Edition')    AS Edition;
Review before runningT-SQLUTF-87 lines
  1. Identify the servicing path

    Open the CVE and find the CU, GDR, service-pack, or feature-pack row that matches the installed SQL Server release.

  2. Check the KB prerequisites

    The MSRC base product version is not an affected-build boundary. Use the linked KB to confirm which earlier builds can take that update.

  3. Verify the resulting build

    After patching, confirm that ProductVersion matches or exceeds the build published by Microsoft for the selected update path.

Treat an exploited CVE as urgent. You still need the correct CU or GDR, a backup and rollback plan, and a tested validation check. Continue with the SQL Server updates list and patching guide.

Data source

Microsoft Security Response Center

The Microsoft Security Response Center (MSRC) publishes Microsoft's vulnerability advisories and Security Update Guide. It records which products are affected and which security updates address them.

This tracker reads its CVEs, revisions, severity ratings, affected update paths, builds, exploitation flags, and KB links from MSRC. Open the Microsoft record before patching because affected products and guidance can change after publication.

Open the MSRC Security Update Guide

Microsoft CVE details, revision history, severity, affected update paths, security-update builds, and KB links.

Status

Checked

Records

318 CVEs

SQL Server vulnerability FAQ

Where should I check for SQL Server vulnerabilities?

+

Microsoft Security Response Center is the source for this SQL Server CVE tracker. Its records provide revision history, severity, affected update paths, builds installed by each security update, exploitation status, and Knowledge Base links.

How do I know whether a CVE affects my SQL Server build?

+

Get the ProductVersion, ProductLevel, and edition from the server. Identify its CU, GDR, or service-pack path, then open the matching Microsoft KB and check the prerequisites. A release year or MSRC base product version alone is too broad to confirm exposure.

What does Microsoft: exploited mean?

+

It means MSRC marks the vulnerability as exploited. Treat it as a prioritization flag, then confirm the affected product, build, attack conditions, and applicable Microsoft security update.

Does a critical CVSS score mean my SQL Server is vulnerable?

+

No. CVSS describes technical severity. Exposure depends on the affected SQL Server product, installed build, configuration, access path, and the conditions described in the Microsoft advisory.

How current is this SQL Server CVE list?

+

The Last checked date shows when MSRC was most recently read. Newest Microsoft revisions appear first. Open the Microsoft record before patching because affected products, FAQs, and update guidance can change after publication.