The archive

#SQL Server

Practical IT guides, comparisons, explainers and news — curated by practitioners.

7articles
14Topics
~3Avg min read
29Total views

7 articles · Curated and written by practitioners

FeaturedMicrosoft update KB5090408, which patches a CVSS 8.8 remote code execution vulnerability in SQL Server 2019 GDR.
SQL Server

KB5090408 Patches CVSS 8.8 RCE in SQL Server 2019 GDR

KB5090408 patches CVE-2026-40370 (CVSS 8.8 RCE via path manipulation) in SQL Server 2019 GDR. Build 15.0.2170.1. For instances on the GDR servicing branch (no CUs). MSDASQL Msg 7416 breaking change. Superseded by KB5102336.

May 13, 2026, 3:30 AM 2 min
5 Trending
EEmanuel De Almeida
Read article
Microsoft security update KB5090407 protecting SQL Server 2019 CU32 from a CVSS 8.8 path manipulation remote code execution.
SQL Server

KB5090407 Patches CVSS 8.8 Path Manipulation RCE in SQL Server 2019 CU32

KB5090407 patches CVE-2026-40370 (CVSS 8.8 RCE via path manipulation) in SQL Server 2019 CU32. Build 15.0.4470.1. MSDASQL linked server queries with @provstr fail with Msg 7416 after installation.

May 13, 2026, 1:30 AM 3 min
5
EEmanuel De Almeida
Microsoft update KB5089900, which patches a critical SQL Server 2022 Analysis Services remote code execution flaw and a.
Microsoft

Microsoft Patches SQL Server 2022 Analysis Services RCE and Database Engine Escalation in KB5089900

Microsoft released KB5089900 on May 12, 2026, a security update for SQL Server 2022 CU24 patching CVE-2026-0234 (privilege escalation), CVE-2026-0235 (SSAS RCE), CVE-2026-0236 (SSRS info disclosure), and CVE-2026-0237 (DoS).

May 13, 2026, 1:00 AM 4 min
5
EEmanuel De Almeida
Microsoft update KB5083252, which patches elevation-of-privilege and SQL injection vulnerabilities in SQL Server 2022 CU24.
SQL Server

KB5083252 Patches EoP and SQL Injection in SQL Server 2022 CU24

KB5083252 patches CVE-2026-32167 (SQL injection EoP), CVE-2026-32176 (PolyBase EoP), and a SQL injection in system stored procedures in SQL Server 2022 CU24. Build 16.0.4250.1. MSDASQL breaking change.

Apr 15, 2026, 2:30 AM 2 min
5
EEmanuel De Almeida
Microsoft security update KB5084816 protecting SQL Server 2019 CU32 from SQL injection and PolyBase elevation-of-privilege.
SQL Server

KB5084816 Patches SQL Injection and PolyBase EoP in SQL Server 2019 CU32

KB5084816 patches CVE-2026-32167 (CVSS 6.7, SQL injection in internal stored procedures) and CVE-2026-32176 (PolyBase linked server EoP) in SQL Server 2019 CU32. Build 15.0.4465.1. Superseded by KB5090407.

Apr 15, 2026, 2:00 AM 3 min
5
EEmanuel De Almeida
Microsoft update KB5083252, which patches a PolyBase elevation-of-privilege flaw and SQL injection vulnerability in SQL.
SQL Server

Microsoft Patches SQL Server 2022 CU24 PolyBase EoP and SQL Injection with KB5083252

Microsoft released KB5083252 on April 14, 2026, a security update for SQL Server 2022 CU24 patching CVE-2026-32167 (PolyBase EoP), CVE-2026-32176 (EoP), and SQL injection in stored procedures. Build 16.0.4250.1.

Apr 15, 2026, 1:30 AM 3 min
2
EEmanuel De Almeida
Microsoft update KB5077469, which patches a Merge Replication elevation-of-privilege vulnerability in SQL Server 2019 CU32.
SQL Server

KB5077469 Patches Merge Replication EoP in SQL Server 2019 CU32

KB5077469 patches CVE-2026-21262 (merge replication EoP) and CVE-2026-26115 in SQL Server 2019 CU32. Build 15.0.4460.4. First of three consecutive monthly SQL Server 2019 EoP patches. Now superseded by KB5102335 (July).

Mar 11, 2026, 2:30 AM 2 min
2
EEmanuel De Almeida