CVE-2026-40370HighCVSS 8.8

SQL Server Remote Code Execution Vulnerability

Published
May 22, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

🎯 Affected products10

  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)
  • Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack
  • Microsoft SQL Server 2017 for x64-based Systems (CU 31)
  • Microsoft SQL Server 2017 for x64-based Systems (GDR)
  • Microsoft SQL Server 2019 for x64-based Systems (CU 32)
  • Microsoft SQL Server 2019 for x64-based Systems (GDR)
  • Microsoft SQL Server 2022 for x64-based Systems (CU 24)
  • Microsoft SQL Server 2022 for x64-based Systems (GDR)
  • Microsoft SQL Server 2025 for x64-based Systems (CU4)
  • Microsoft SQL Server 2025 for x64-based Systems (GDR)

✅ Remediation

KB5089899 (Security Update) — fixed build 17.0.4040.1 KB5089900 (Security Update) — fixed build 16.0.4252.3 KB5090347 (Security Update) — fixed build 14.0.2110.2 KB5090408 (Security Update) — fixed build 15.0.2170.1 KB5089271 (Security Update) — fixed build 13.0.6490.1 KB5089270 (Security Update) — fixed build 13.0.7085.1 KB5090354 (Security Update) — fixed build 14.0.3530.2 KB5091158 (Security Update) — fixed build 16.0.1180.1 KB5091223 (Security Update) — fixed build 17.0.1115.1 KB5090407 (Security Update) — fixed build 15.0.4470.1

🔗 References (21)