Skip to main content
E
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2026-40370
CVE-2026-40370
Remote Code Execution
CVSS
8.8
SQL Server Remote Code Execution Vulnerability
Vendor
Microsoft Security Response Center (MSRC)
Published
May 22, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2026-40370 →
📋 Description
<p>External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.</p>