CVE-2026-47297: Microsoft SQL Server Remote Code Execution Vulnerability
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4060.2Patch KB5101346 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4275.2Patch KB5122768 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4085.5Patch KB5122769 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.2190.7Patch KB5122773 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.1135.8Patch KB5122770 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.4262.2Patch KB5101347 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.1200.5Patch KB5122771 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.4490.9Patch KB5122772
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is rated network-accessible and requires no privileges or user interaction. However, the attack complexity is rated high.
What is the potential impact of a successful exploit?
Successful exploitation can allow remote code execution in SQL Server. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
Which SQL Server releases are identified as affected?
The provided software list includes Microsoft SQL Server 2019, SQL Server 2022, and SQL Server 2025, including SQL Server 2019 CU 32, SQL Server 2022 CU 25 and CU 26, and SQL Server 2025 CU6 and CU8.