Security advisoryView advisory
MicrosoftHighResolvedUpdated Jul 19, 2026

KB5077469 Patches Merge Replication EoP in SQL Server 2019 CU32

March 2026 security update for SQL Server 2019 CU32 patches CVE-2026-21262 (merge replication EoP) and CVE-2026-26115 (EoP). Build 15.0.4460.4. Superseded by KB5084816 (April) and KB5090407 (May).

Emanuel De AlmeidaMar 11, 2026, 2:30 AM2 min read
Severity
High
Status
Resolved
Entity
Microsoft SQL Server 2019
Confirmed by
Microsoft Support

Microsoft released KB5077469 on March 10, 2026, a security update for SQL Server 2019 CU32 patching CVE-2026-21262 and CVE-2026-26115, both elevation of privilege vulnerabilities. Per Microsoft's KB article, CVE-2026-21262 targets the merge replication version upgrade process, allowing authenticated users to escalate privileges during routine maintenance.

This is the first of three consecutive monthly SQL Server 2019 CU32 security updates (March, April, May), each patching different EoP vectors. Install the latest GDR (KB5102335) for complete coverage.

Key takeaways

  • CVE-2026-21262: EoP in merge replication version upgrade process.
  • CVE-2026-26115: additional EoP in Database Engine.
  • Build 15.0.4460.4. First of three monthly SQL Server 2019 CU32 GDRs.

Affected

Vendors
Microsoft
Products
SQL Server 2019 (Windows)SQL Server 2019 (Linux)
CVEs
CVE-2026-21262CVE-2026-26115

KB5077469 Patches Merge Replication EoP in SQL Server 2019 CU32

Microsoft released KB5077469 on March 10, 2026, a security update for SQL Server 2019 CU32. Per Microsoft's KB article, it patches CVE-2026-21262 and CVE-2026-26115, both elevation of privilege vulnerabilities. The product version updates to 15.0.4460.4.

Per the official KB, CVE-2026-21262 targets the merge replication version upgrade process. An authenticated user can exploit the upgrade path to escalate privileges. This is the first of three consecutive monthly SQL Server 2019 CU32 security updates, followed by KB5084816 (April, CVE-2026-32167/32176) and KB5090407 (May, CVE-2026-40370).

Merge Replication EoP During Routine Upgrades

Organizations using SQL Server 2019 merge replication are directly exposed. The vulnerability is in the version upgrade process, meaning it can be triggered during routine maintenance operations. KB5077469 is superseded by KB5084816 (April, Build 15.0.4465.1), KB5090407 (May, Build 15.0.4470.1), and KB5102335 (July, Build 15.0.4480.2). Install the latest GDR.

All SQL Server 2019 Editions

SQL Server 2019 RTM with any CU applied, Windows and Linux, all editions. Build 15.0.4460.4. No MSDASQL breaking change in this update (that was introduced in KB5084816 April). Superseded by three subsequent updates.

Timeline

Mar 10, 2026
KB5077469 releasedMicrosoft releases KB5077469 for SQL Server 2019 CU32.

Impact & actions

Two EoP vulnerabilities in SQL Server 2019 CU32 including merge replication upgrade path.

Security: CVE-2026-21262 enables privilege escalation through merge replication upgrades.

Recommended actions · High urgency

  1. 1Install KB5102335 (latest GDR).
  2. 2Review merge replication configuration permissions.

Technical details

CVEs
CVE-2026-21262, CVE-2026-26115
Affected versions
SQL Server 2019 (before 15.0.4460.4)
Patched versions
SQL Server 2019 Build 15.0.4460.4

Mitigations

  • Install KB5102335 (latest).
  • Restrict merge replication permissions.

Response

FAQ

What does KB5077469 fix?

CVE-2026-21262 (merge replication version upgrade EoP) and CVE-2026-26115 (EoP). Build 15.0.4460.4.

Is this the latest SQL Server 2019 update?

No. Install KB5102335 (July 2026, Build 15.0.4480.2) for the latest protection.

Which systems are affected?

SQL Server 2019 RTM with any CU, Windows and Linux, all editions.

The bottom line

KB5077469 patches CVE-2026-21262 (merge replication EoP) and CVE-2026-26115 in SQL Server 2019 CU32. Build 15.0.4460.4. Now three updates behind.

What happens next

KB5084816 (April), KB5090407 (May), KB5102335 (July) supersede this update.

What to do

Install KB5102335 (July). Review merge replication permissions.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles