CVE-2026-54117: Microsoft SQL Server Remote Code Execution Vulnerability
Published Jul 14, 2026
·Updated
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
12 affected componentsFixes available
Microsoft SQL Server 2025<17.0.1125.2
17.0.1125.2
Microsoft SQL Server 2025 (CU6)<17.0.4060.2
17.0.4060.2
Microsoft SQL Server 2016>=13.0.6300.2<13.0.6500.1
Microsoft SQL Server 2016>=13.0.7000.253<13.0.7095.1
Microsoft SQL Server 2017>=14.0.1000.169<14.0.2120.1
Microsoft SQL Server 2017>=14.0.3006.16<14.0.3540.1
Microsoft SQL Server 2019>=15.0.2000.5<15.0.2180.2
Microsoft SQL Server 2019>=15.0.4003.23<15.0.4480.2
Microsoft SQL Server 2022>=16.0.1000.6<16.0.1190.2
Microsoft SQL Server 2022>=16.0.4003.1<16.0.4262.2
Microsoft SQL Server 2025>=17.0.1000.7<17.0.1125.2
Microsoft SQL Server 2025>=17.0.4006.2<17.0.4060.2
Remediation
Event History
Jul 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-54117?
CVE-2026-54117 has a high severity rating of 8.8 on the CVSS scale.
2
What type of vulnerability is CVE-2026-54117?
CVE-2026-54117 is a remote code execution vulnerability due to deserialization of untrusted data in Microsoft SQL Server.
3
Who is affected by CVE-2026-54117?
CVE-2026-54117 affects various versions of Microsoft SQL Server, including 2016, 2017, 2019, and 2022.
4
How do I fix CVE-2026-54117?
To fix CVE-2026-54117, apply the available security patch provided by Microsoft.
5
What is the risk associated with CVE-2026-54117?
The risk associated with CVE-2026-54117 is high, as it allows an authorized attacker to execute code remotely.