CVE-2026-40370: SQL Server Remote Code Execution Vulnerability
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
Other sources
SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1115.1Patch KB5091223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4470.1Patch KB5090407 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.3530.2Patch KB5090354 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4040.1Patch KB5089899 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1180.1Patch KB5091158 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.6490.1Patch KB5089271 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.0.2110.2Patch KB5090347 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2170.1Patch KB5090408 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.0.7085.1Patch KB5089270 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4252.3Patch KB5089900
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40370?
CVE-2026-40370 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2026-40370?
You can fix CVE-2026-40370 by applying the latest security patches provided by Microsoft for the affected SQL Server versions.
Which SQL Server versions are affected by CVE-2026-40370?
CVE-2026-40370 affects SQL Server 2016, 2017, 2019, and 2022 in specific cumulative updates.
Can CVE-2026-40370 be exploited without authentication?
No, CVE-2026-40370 requires an attacker to be authorized, allowing exploitation only by authenticated users.
What type of attack does CVE-2026-40370 enable?
CVE-2026-40370 enables remote code execution attacks, allowing malicious code to be executed over a network.