Microsoft released KB5077469 on March 10, 2026, a security update for SQL Server 2019 CU32 patching CVE-2026-21262 and CVE-2026-26115, both elevation of privilege vulnerabilities. Per Microsoft's KB article, CVE-2026-21262 targets the merge replication version upgrade process, allowing authenticated users to escalate privileges during routine maintenance.
This is the first of three consecutive monthly SQL Server 2019 CU32 security updates (March, April, May), each patching different EoP vectors. Install the latest GDR (KB5102335) for complete coverage.
Key takeaways
- CVE-2026-21262: EoP in merge replication version upgrade process.
- CVE-2026-26115: additional EoP in Database Engine.
- Build 15.0.4460.4. First of three monthly SQL Server 2019 CU32 GDRs.
Affected
KB5077469 Patches Merge Replication EoP in SQL Server 2019 CU32
Microsoft released KB5077469 on March 10, 2026, a security update for SQL Server 2019 CU32. Per Microsoft's KB article, it patches CVE-2026-21262 and CVE-2026-26115, both elevation of privilege vulnerabilities. The product version updates to 15.0.4460.4.
Per the official KB, CVE-2026-21262 targets the merge replication version upgrade process. An authenticated user can exploit the upgrade path to escalate privileges. This is the first of three consecutive monthly SQL Server 2019 CU32 security updates, followed by KB5084816 (April, CVE-2026-32167/32176) and KB5090407 (May, CVE-2026-40370).
Merge Replication EoP During Routine Upgrades
Organizations using SQL Server 2019 merge replication are directly exposed. The vulnerability is in the version upgrade process, meaning it can be triggered during routine maintenance operations. KB5077469 is superseded by KB5084816 (April, Build 15.0.4465.1), KB5090407 (May, Build 15.0.4470.1), and KB5102335 (July, Build 15.0.4480.2). Install the latest GDR.
All SQL Server 2019 Editions
SQL Server 2019 RTM with any CU applied, Windows and Linux, all editions. Build 15.0.4460.4. No MSDASQL breaking change in this update (that was introduced in KB5084816 April). Superseded by three subsequent updates.
Timeline
Impact & actions
Two EoP vulnerabilities in SQL Server 2019 CU32 including merge replication upgrade path.
Security: CVE-2026-21262 enables privilege escalation through merge replication upgrades.
Recommended actions · High urgency
- 1Install KB5102335 (latest GDR).
- 2Review merge replication configuration permissions.
Technical details
- CVEs
- CVE-2026-21262, CVE-2026-26115
- Affected versions
- SQL Server 2019 (before 15.0.4460.4)
- Patched versions
- SQL Server 2019 Build 15.0.4460.4
Mitigations
- Install KB5102335 (latest).
- Restrict merge replication permissions.
Response
FAQ
What does KB5077469 fix?
CVE-2026-21262 (merge replication version upgrade EoP) and CVE-2026-26115 (EoP). Build 15.0.4460.4.
Is this the latest SQL Server 2019 update?
No. Install KB5102335 (July 2026, Build 15.0.4480.2) for the latest protection.
Which systems are affected?
SQL Server 2019 RTM with any CU, Windows and Linux, all editions.
The bottom line
KB5077469 patches CVE-2026-21262 (merge replication EoP) and CVE-2026-26115 in SQL Server 2019 CU32. Build 15.0.4460.4. Now three updates behind.
What happens next
What to do






