CVE-2026-54118: Microsoft SQL Server Remote Code Execution Vulnerability
Published Jul 14, 2026
·Updated
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Other sources
Microsoft SQL Server Remote Code Execution Vulnerability
— Microsoft
Affected Software
20 affected componentsFixes available
Microsoft SQL Server 2022<16.0.1190.2
16.0.1190.2
Microsoft SQL Server 2025 (CU6)<17.0.4060.2
17.0.4060.2
Microsoft SQL Server 2017 (CU 31)<14.0.3540.1
14.0.3540.1
Microsoft SQL Server 2016<13.0.6500.1
13.0.6500.1
Microsoft SQL Server 2017<14.0.2120.1
14.0.2120.1
Microsoft SQL Server 2019 (CU 32)<15.0.4480.2
15.0.4480.2
Microsoft SQL Server 2022 (CU 25)<16.0.4262.2
16.0.4262.2
Microsoft SQL Server 2019<15.0.2180.2
15.0.2180.2
Microsoft SQL Server 2025<17.0.1125.2
17.0.1125.2
Microsoft SQL Server 2016 Azure Connect Feature Pack<13.0.7095.1
13.0.7095.1
Microsoft SQL Server 2016>=13.0.6300.2<13.0.6500.1
Microsoft SQL Server 2016>=13.0.7000.253<13.0.7095.1
Microsoft SQL Server 2017>=14.0.1000.169<14.0.2120.1
Microsoft SQL Server 2017>=14.0.3006.16<14.0.3540.1
Microsoft SQL Server 2019>=15.0.2000.5<15.0.2180.2
Microsoft SQL Server 2019>=15.0.4003.23<15.0.4480.2
Microsoft SQL Server 2022>=16.0.1000.6<16.0.1190.2
Microsoft SQL Server 2022>=16.0.4003.1<16.0.4262.2
Microsoft SQL Server 2025>=17.0.1000.7<17.0.1125.2
Microsoft SQL Server 2025>=17.0.4006.2<17.0.4060.2
Remediation
Event History
Jul 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
Updated
via Microsoft·02:00 PM
DescriptionSeverity
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionSeverity
Data Sourced
via NVD·05:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-54118?
The severity of CVE-2026-54118 is rated high with a score of 8.8.
2
How do I fix CVE-2026-54118?
To fix CVE-2026-54118, apply the latest security updates from Microsoft for the affected SQL Server versions.
3
Who is affected by CVE-2026-54118?
CVE-2026-54118 affects users of Microsoft SQL Server 2016, 2017, 2019, 2022, and 2025.
4
What is the impact of CVE-2026-54118?
CVE-2026-54118 allows an authorized attacker to execute code remotely over a network.
5
How can I mitigate the risks associated with CVE-2026-54118?
Mitigation for CVE-2026-54118 involves restricting network access to the SQL Server and applying patches promptly.