4 articles · Curated and written by practitioners

KB5090408 Patches CVSS 8.8 RCE in SQL Server 2019 GDR
KB5090408 patches CVE-2026-40370 (CVSS 8.8 RCE via path manipulation) in SQL Server 2019 GDR. Build 15.0.2170.1. For instances on the GDR servicing branch (no CUs). MSDASQL Msg 7416 breaking change. Superseded by KB5102336.

KB5090407 Patches CVSS 8.8 Path Manipulation RCE in SQL Server 2019 CU32
KB5090407 patches CVE-2026-40370 (CVSS 8.8 RCE via path manipulation) in SQL Server 2019 CU32. Build 15.0.4470.1. MSDASQL linked server queries with @provstr fail with Msg 7416 after installation.

KB5084816 Patches SQL Injection and PolyBase EoP in SQL Server 2019 CU32
KB5084816 patches CVE-2026-32167 (CVSS 6.7, SQL injection in internal stored procedures) and CVE-2026-32176 (PolyBase linked server EoP) in SQL Server 2019 CU32. Build 15.0.4465.1. Superseded by KB5090407.

KB5077469 Patches Merge Replication EoP in SQL Server 2019 CU32
KB5077469 patches CVE-2026-21262 (merge replication EoP) and CVE-2026-26115 in SQL Server 2019 CU32. Build 15.0.4460.4. First of three consecutive monthly SQL Server 2019 EoP patches. Now superseded by KB5102335 (July).

