CVE-2026-47297HighCVSS 8.1
Microsoft SQL Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
🎯 Affected products6
- Microsoft SQL Server 2019 for x64-based Systems (CU 32)
- Microsoft SQL Server 2019 for x64-based Systems (GDR)
- Microsoft SQL Server 2022 for x64-based Systems (CU 26)
- Microsoft SQL Server 2022 for x64-based Systems (GDR)
- Microsoft SQL Server 2025 for x64-based Systems (CU8)
- Microsoft SQL Server 2025 for x64-based Systems (GDR)
✅ Remediation
KB5122773 (Security Update) — fixed build 15.0.2190.7 KB5122771 (Security Update) — fixed build 16.0.1200.5 KB5122770 (Security Update) — fixed build 17.0.1135.8 KB5122772 (Security Update) — fixed build 15.0.4490.9 KB5122769 (Security Update) — fixed build 17.0.4085.5 KB5122768 (Security Update) — fixed build 16.0.4275.2
🔗 References (13)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47297
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e668fe5f-ea1e-41fb-97f7-1bc12e91150b
- referencehttps://support.microsoft.com/help/5122773
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7ce0ba48-9a1e-4298-b300-79f251385092
- referencehttps://support.microsoft.com/help/5122771
- patchhttps://www.microsoft.com/download/details.aspx?familyid=0d644af6-717c-45d7-bf71-ce7e309d2ad7
- referencehttps://support.microsoft.com/help/5122770
- patchhttps://www.microsoft.com/download/details.aspx?familyid=cee52a4a-832a-447e-909d-0f629cab835f
- referencehttps://support.microsoft.com/help/5122772
- patchhttps://www.microsoft.com/download/details.aspx?familyid=65b5f47b-53bf-4b54-89e7-6aefaad8dc51
- referencehttps://support.microsoft.com/help/5122769
- patchhttps://www.microsoft.com/download/details.aspx?familyid=d682ec86-56e1-45c3-a0fa-552f89f6e51e
- referencehttps://support.microsoft.com/help/5122768