SQL Server 2025 Updates & Release Notes

Follow

43 updates curated from 48 sources by the Releasebot Team. Last updated: Oct 4, 2026

Get this feed:
  • Sep 15, 2026
    • Date parsed from source:
      Sep 15, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5122048 - Cumulative Update 9 for SQL Server 2025

    SQL Server 2025 releases Cumulative Update 9 with 45 fixes, refreshed build updates, and a downloadable workbook of build and support details. It also calls out known issues around SESSION_CONTEXT, linked server queries, and sys.dm_exec_requests during recovery.

    This article describes Cumulative Update 9 (CU9) for Microsoft SQL Server 2025. This update package contains 45 fixes that were issued after the release of SQL Server 2025 Cumulative Update 8. It updates components in the following builds:

    • SQL Server - Product version: 17.0.5005.3, file version: 2025.170.5005.3
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.
    For more information, see the Known issues section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.
    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.
    The SQL Server error log contains entries that resemble the following text:

    The database '' is marked RESTORING and is in a state that does not allow recovery to be run.
    ***Stack Dump being sent to \SQLDump0215.txt
    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.

    BEGIN STACK DUMP:
    07/30/26 07:37:23 spid 77

    Exception Address = 0x7FFDED94970D
    Exception Code = c0000005 EXCEPTION_ACCESS_VIOLATION
    Access Violation occurred reading address 00000000000000F0
    Input Buffer bytes -
    <dbo.sp_YourMonitoringStoredProcedure>

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.
    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error 976 or error 978, as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    [Table of bug fixes and improvements with bug reference IDs, descriptions, fix areas, components, and platforms]

    How to obtain or download this CU or the latest CU package

    File information

    Notes for this update

    How to uninstall this update

    References

    • Announcing updates to the SQL Server Incremental Servicing Model (ISM)
    • SQL Server Service Packs are no longer supported starting from SQL Server 2017
    • Determine which version and edition of SQL Server Database Engine is running
    • Servicing models for SQL Server
    • Naming schema and Fix area descriptions for SQL Server software update packages
    • Description of the standard terminology that is used to describe Microsoft software updates
    Original source
  • Sep 15, 2026
    • Date parsed from source:
      Sep 15, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5122048 - Cumulative Update 9 for SQL Server 2025

    SQL Server 2025 ships Cumulative Update 9 with 44 fixes and build updates across the platform, plus important notes on known issues, security guidance, and download and uninstall details for Windows and Linux.

    This article describes Cumulative Update 9 (CU9) for Microsoft SQL Server 2025. This update package contains 44 fixes that were issued after the release of SQL Server 2025 Cumulative Update 8. It updates components in the following builds:

    • SQL Server - Product version: 17.0.5005.3, file version: 2025.170.5005.3
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files if they're run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.

    For more information, see the "Known issues" section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the database engine can reject connections for certain linked server configurations that use the MSDASQL provider. This issue occurs even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.

    The SQL Server error log contains entries that resemble the following text:

    The database '' is marked RESTORING and is in a state that does not allow recovery to be run.
    ***Stack Dump being sent to \SQLDump0215.txt
    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.

    BEGIN STACK DUMP:
    07/30/26 07:37:23 spid 77

    Exception Address = 0x7FFDED94970D
    Exception Code = c0000005 EXCEPTION_ACCESS_VIOLATION
    Access Violation occurred reading address 00000000000000F0
    Input Buffer bytes -
    <dbo.sp_YourMonitoringStoredProcedure>

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.

    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error 976 or error 978, as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    [The table lists numerous bug fixes, improvements, and security updates across various components such as SQL Server Engine, Security Infrastructure, Management Services, SQL Server Client Tools, XML, PolyBase, Replication, Query Optimizer, and others. Each entry includes a bug reference number, description, fix area, component, and platform.]

    How to obtain or download this CU or the latest CU package

    [Sections with instructions on obtaining or downloading the update for Windows and Linux]

    File information

    [Sections with file hash information and cumulative update package file information]

    Notes for this update

    [Sections with prerequisites, restart information, registry information, important notices, hybrid environment deployment, language support, components updated, and support for this update]

    How to uninstall this update

    [Sections with instructions on uninstalling the update on Windows and Linux]

    References

    • Announcing updates to the SQL Server Incremental Servicing Model (ISM)
    • SQL Server Service Packs are no longer supported starting from SQL Server 2017
    • Determine which version and edition of SQL Server Database Engine is running
    • Servicing models for SQL Server
    • Naming schema and Fix area descriptions for SQL Server software update packages
    • Description of the standard terminology that is used to describe Microsoft software updates
    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Microsoft and hundreds of other software products.

    Create account
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5122769 - Description of the security update for SQL Server 2025 CU8: September 8, 2026

    SQL Server 2025 ships a security update for Windows and Linux that fixes vulnerabilities and improves protection across the platform. It updates the engine to 17.0.4085.5 and includes known issue notes plus guidance for applying the patch.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Release date: September 8, 2026

    Version: 17.0.4085.5

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-66814 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66816 - Microsoft SQL Server Security Feature Bypass Vulnerability
    • CVE-2026-66818 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66819 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66820 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67368 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67369 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67370 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67373 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67376 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67378 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67379 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67380 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67381 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67383 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67384 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67385 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67386 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67388 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67389 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67390 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67393 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67624 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67629 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67630 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67631 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67633 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67636 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67638 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67639 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67641 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67642 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67643 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67645 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67648 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68775 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68776 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68777 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68778 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68779 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68780 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68781 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68784 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68785 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68786 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68787 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-73028 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-73029 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-77480 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77481 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77483 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77484 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77485 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77487 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77488 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-47297 - Microsoft SQL Server Remote Code Execution Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.4085.5, file version: 2025.170.4085.5

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16

    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.

    The SQL Server error log contains entries that resemble the following text:

    The database '' is marked RESTORING and is in a state that does not allow recovery to be run.

    ***Stack Dump being sent to \SQLDump0215.txt

    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.

    BEGIN STACK DUMP:

    07/30/26 07:37:23 spid 77

    Exception Address = 0x7FFDED94970D

    Exception Code = c0000005 EXCEPTION_ACCESS_VIOLATION

    Access Violation occurred reading address 00000000000000F0

    Input Buffer bytes -

    <dbo.sp_YourMonitoringStoredProcedure>

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.

    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error "976" or error "978" as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.

    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    [Table of bug fixes and improvements with bug reference IDs, descriptions, fix areas, components, and platforms]

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:

    Download the package now

    How to obtain or download the latest cumulative update package for Linux

    To update SQL Server 2025 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command.

    For installation instructions and direct links to the CU package downloads, see the SQL Server 2025 Release Notes.

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 CU release through this SQL Server 2025 CU8 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name: SQLServer2025-KB5122769-x64.exe

    SHA256 hash: 6E23BA9E542DF038D57383568C0AEE7D2F59AAD6413D08C6AADA72FBD7F87CD0

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it's converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5122769.

    Information about protection and security

    Protect yourself online: Windows Security support

    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5122770 - Description of the security update for SQL Server 2025 GDR: September 8, 2026

    SQL Server 2025 ships a security update for Windows and Linux that fixes vulnerabilities and delivers broad engine improvements across backup, replication, query processing, security, and more, while also noting a known issue with linked server queries that use MSDASQL.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Release date: September 8, 2026
    Version: 17.0.1135.8

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-66814 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66816 - Microsoft SQL Server Security Feature Bypass Vulnerability
    • CVE-2026-66818 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66819 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66820 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67368 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67369 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67370 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67373 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67376 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67378 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67379 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67380 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67381 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67383 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67384 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67385 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67386 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67388 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67389 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67390 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67393 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67624 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67629 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67630 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67631 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67633 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67636 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67638 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67639 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67641 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67642 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67643 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67645 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67648 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68775 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68776 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68777 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68778 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68779 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68780 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68781 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68784 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68785 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68786 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68787 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-73028 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-73029 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-77480 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77481 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77483 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77484 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77485 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77487 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77488 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-47297 - Microsoft SQL Server Remote Code Execution Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.1135.8, file version: 2025.170.1135.8

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.
    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    [Extensive list of bug fixes and improvements related to SQL Server Engine components including Backup Restore, SQL Agent, WMI Management Provider, Security Infrastructure, Replication, In-Memory OLTP, PolyBase, XML, Query Execution, Programmability, Extended Events, and Query Store across Windows and Linux platforms.]

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:
    Download the package now.

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 GDR release through this SQL Server 2025 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name: SQLServer2025-KB5122770-x64.exe
    SHA256 hash: AC63E4C646B6229D35B4A4F7B6AF25DD3A16A4DAE23488227F3FAD99C13C33F3

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5122770.

    Information about protection and security

    Protect yourself online: Windows Security support
    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5122769 - Description of the security update for SQL Server 2025 CU8: September 8, 2026

    SQL Server 2025 ships a security update for Windows and Linux that fixes multiple vulnerabilities and includes additional engine reliability and security fixes. It also updates the product build and notes a couple of known issues with linked servers and database recovery queries.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-66814 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66816 - Microsoft SQL Server Security Feature Bypass Vulnerability
    • CVE-2026-66818 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66819 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66820 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67368 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67369 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67370 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67373 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67376 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67378 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67379 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67380 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67381 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67383 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67384 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67385 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67386 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67388 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67389 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67390 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67393 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67624 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67629 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67630 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67631 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67633 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67636 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67638 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67639 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67641 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67642 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67643 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67645 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67648 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68775 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68776 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68777 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68778 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68779 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68780 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68781 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68784 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68785 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68786 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68787 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-73028 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-73029 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-77480 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77481 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77483 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77484 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77485 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77487 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77488 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-47297 - Microsoft SQL Server Remote Code Execution Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.4085.5, file version: 2025.170.4085.5

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.
    

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.

    The SQL Server error log contains entries that resemble the following text:

    The database '<DatabaseName>' is marked RESTORING and is in a state that does not allow recovery to be run.
    ***Stack Dump being sent to <SQLServerLogFolder>\SQLDump0215.txt
    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.
    *******************************************************************************
    
    BEGIN STACK DUMP:
      07/30/26 07:37:23 spid 77
    
    Exception Address = 0x7FFDED94970D
    Exception Code    = c0000005 EXCEPTION_ACCESS_VIOLATION
    Access Violation occurred reading address 00000000000000F0
    Input Buffer <size> bytes -
              <dbo.sp_YourMonitoringStoredProcedure>
    

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.

    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error "976" or error "978" as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.

    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    [Table of numerous bug fixes and descriptions related to SQL Server Engine components, including SQL Agent, PolyBase, Security Infrastructure, Backup Restore, Query Execution, Replication, Extended Events, XML, In-Memory OLTP, and others, covering various security, reliability, and functionality improvements.]

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:

    Download the package now.

    How to obtain or download the latest cumulative update package for Linux

    To update SQL Server 2025 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command.

    For installation instructions and direct links to the CU package downloads, see the SQL Server 2025 Release Notes.

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 CU release through this SQL Server 2025 CU8 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name: SQLServer2025-KB5122769-x64.exe

    SHA256 hash: 6E23BA9E542DF038D57383568C0AEE7D2F59AAD6413D08C6AADA72FBD7F87CD0

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it's converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5122769.

    Information about protection and security

    Protect yourself online: Windows Security support

    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Similar to SQL Server 2025 with recent updates:

  • Sep 8, 2026
    • Date parsed from source:
      Sep 8, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5122770 - Description of the security update for SQL Server 2025 GDR: September 8, 2026

    SQL Server 2025 ships a broad security update for Windows and Linux that fixes vulnerabilities, adds important protections and includes build updates plus known issue notes for linked server queries using MSDASQL.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-66814 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66816 - Microsoft SQL Server Security Feature Bypass Vulnerability
    • CVE-2026-66818 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66819 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-66820 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67368 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67369 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67370 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67373 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67376 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67378 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67379 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67380 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67381 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-67383 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67384 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67385 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67386 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67388 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67389 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67390 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67393 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67624 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67629 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67630 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67631 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67633 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67636 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67638 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67639 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67641 - Microsoft SQL Server Denial of Service Vulnerability
    • CVE-2026-67642 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67643 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-67645 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-67648 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68775 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68776 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68777 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68778 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68779 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68780 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68781 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68784 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-68785 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68786 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-68787 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-73028 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-73029 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-77480 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77481 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77483 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77484 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-77485 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77487 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-77488 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-47297 - Microsoft SQL Server Remote Code Execution Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.1135.8, file version: 2025.170.1135.8

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.
    

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.

    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    [Detailed list of fixes and improvements with bug references and descriptions]

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:

    Download the package now.

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any release through this SQL Server 2025 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name: SQLServer2025-KB5122770-x64.exe

    SHA256 hash: AC63E4C646B6229D35B4A4F7B6AF25DD3A16A4DAE23488227F3FAD99C13C33F3

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5122770.

    Information about protection and security

    Protect yourself online: Windows Security support

    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Aug 13, 2026
    • Date parsed from source:
      Aug 13, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5104822 - Cumulative Update 8 for SQL Server 2025

    SQL Server 2025 ships Cumulative Update 8 with 11 fixes, including JSON_MODIFY and OPENJSON corrections, a new optional @multi_subnet_failover parameter for sp_adddistributor, and improvements for restore, setup, Linux, PolyBase, and maintenance plan stability.

    This article describes Cumulative Update 8 (CU8) for Microsoft SQL Server 2025. This update package contains 11 fixes that were issued after the release of SQL Server 2025 Cumulative Update 7. It updates components in the following builds:

    • SQL Server - Product version: 17.0.4075.5, file version: 2025.170.4075.5
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.

    For more information, see the Known issues section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.

    The SQL Server error log contains entries that resemble the following text:

    The database '' is marked RESTORING and is in a state that does not allow recovery to be run.
    ***Stack Dump being sent to \SQLDump0215.txt
    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.

    BEGIN STACK DUMP:
    07/30/26 07:37:23 spid 77

    Exception Address = 0x7FFDED94970D
    Exception Code = c0000005 EXCEPTION_ACCESS_VIOLATION
    Access Violation occurred reading address 00000000000000F0
    Input Buffer bytes -
    <dbo.sp_YourMonitoringStoredProcedure>

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.

    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error 976 or error 978, as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    Bug reference Description Fix area Component Platform 4929794 Fixes an issue in which restoring a database by using Volume Shadow Copy Service (VSS) and WITH MOVE takes a long time or times out if the server contains hundreds of databases. SQL Server Engine Backup Restore Windows 5189710 Adds encryption support for communication between the PolyBase external service and clients that use gRPC on Linux. SQL Server Engine PolyBase Linux 5197076 Fixes an issue in which an index rebuild maintenance plan stops responding because of a long-running query. SQL Server Engine Maintenance Plan All 5379749 Fixes an issue in which SQL Server Setup recommends a max server memory value of 128 GB instead of 256 GB for Standard and Standard Developer editions. SQL Setup Deployment Platform Windows 5400887 Fixes an issue in which changing the collation during initial setup can block mssql-conf unexpectedly on systems that have a high CPU count. SQL Server Engine Linux Linux 5414824 Adds a new optional parameter, @multi_subnet_failover, to sp_adddistributor. SQL Server Engine Replication Windows 5425855 Fixes an issue in which OPENJSON returns unexpected rows when a JSON path contains special pattern-matching characters, including %, _, [, or ]. SQL Server Engine Programmability All 5434644 Fixes an assertion and dump file that occur when DBCC CHECKTABLE runs with EXTENDED_LOGICAL_CHECKS against a persisted computed column that uses the native json data type. SQL Server Engine Programmability All 5446188 Fixes errors 13643 and 7102 that occur when JSON_MODIFY appends a value to a native json array that contains 65,535 elements. SQL Server Engine Programmability All 5446201 Fixes error 13643, state 101, that occurs when JSON_MODIFY receives a native json array that contains 65,536 or more elements as its value argument. SQL Server Engine Programmability All 5446209 Fixes errors 13647 and 13643 that occur when JSON_MODIFY overwrites or deletes a stored native json array that contains 65,536 or more elements. SQL Server Engine Programmability All

    How to obtain or download this CU or the latest CU package

    File information

    Notes for this update

    How to uninstall this update

    References

    • Announcing updates to the SQL Server Incremental Servicing Model (ISM)
    • SQL Server Service Packs are no longer supported starting from SQL Server 2017
    • Determine which version and edition of SQL Server Database Engine is running
    • Servicing models for SQL Server
    • Naming schema and Fix area descriptions for SQL Server software update packages
    • Description of the standard terminology that is used to describe Microsoft software updates
    Original source
  • Aug 13, 2026
    • Date parsed from source:
      Aug 13, 2026
    • First seen by Releasebot:
      Aug 13, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5104822 - Cumulative Update 8 for SQL Server 2025

    SQL Server 2025 ships Cumulative Update 8 with 12 fixes, including backup and restore improvements, PolyBase encryption support on Linux, a new sp_adddistributor parameter, and several JSON, setup, maintenance, and engine bug fixes.

    This article describes Cumulative Update 8 (CU8) for Microsoft SQL Server 2025. This update package contains 12 fixes that were issued after the release of SQL Server 2025 Cumulative Update 7. It updates components in the following builds:

    • SQL Server - Product version: 17.0.4075.5, file version: 2025.170.4075.5
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when they're run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.

    For more information, see the "Known issues" section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the database engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.

    The SQL Server error log contains entries that resemble the following text:

    The database '' is marked RESTORING and is in a state that does not allow recovery to be run.
    ***Stack Dump being sent to \SQLDump0215.txt
    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.

    BEGIN STACK DUMP:
    07/30/26 07:37:23 spid 77

    Exception Address = 0x7FFDED94970D
    Exception Code = c0000005 EXCEPTION_ACCESS_VIOLATION
    Access Violation occurred reading address 00000000000000F0
    Input Buffer bytes -
    <dbo.sp_YourMonitoringStoredProcedure>

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.

    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error 976 or error 978, as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    Bug reference | Description | Fix area | Component | Platform
    4929794 | Fixes an issue in which restoring a database by using Volume Shadow Copy Service (VSS) and WITH MOVE takes a long time or times out if the server contains hundreds of databases. | SQL Server Engine | Backup Restore | Windows
    5189710 | Adds encryption support for communication between the PolyBase external service and clients that use gRPC on Linux. | SQL Server Engine | PolyBase | Linux
    5197076 | Fixes an issue in which an index rebuild maintenance plan stops responding because of a long-running query. | SQL Server Engine | Maintenance Plan | All
    5379749 | Fixes an issue in which SQL Server Setup recommends a max server memory value of 128 GB instead of 256 GB for Standard and Standard Developer editions. | SQL Setup | Deployment Platform | Windows
    5391747 | Fixes an issue in which a Hekaton transaction remains in the Validating state after an internal transaction encounters a validation failure during the preparatory phase when memory-optimized tempdb metadata is enabled. | SQL Server Engine | In-Memory OLTP | All
    5400887 | Fixes an issue in which changing the collation during initial setup can block mssql-conf unexpectedly on systems that have a high CPU count. | SQL Server Engine | Linux | Linux
    5414824 | Adds a new optional parameter, @multi_subnet_failover, to sp_adddistributor. | SQL Server Engine | Replication | Windows
    5425855 | Fixes an issue in which OPENJSON returns unexpected rows when a JSON path contains special pattern-matching characters, including %, _, [, or ]. | SQL Server Engine | Programmability | All
    5434644 | Fixes an assertion and dump file that occur when DBCC CHECKTABLE runs with EXTENDED_LOGICAL_CHECKS against a persisted computed column that uses the native json data type. | SQL Server Engine | Programmability | All
    5446188 | Fixes errors 13643 and 7102 that occur when JSON_MODIFY appends a value to a native json array that contains 65,535 elements. | SQL Server Engine | Programmability | All
    5446201 | Fixes error 13643, state 101, that occurs when JSON_MODIFY receives a native json array that contains 65,536 or more elements as its value argument. | SQL Server Engine | Programmability | All
    5446209 | Fixes errors 13647 and 13643 that occur when JSON_MODIFY overwrites or deletes a stored native json array that contains 65,536 or more elements. | SQL Server Engine | Programmability | All

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5096981 - Cumulative Update 7 for SQL Server 2025

    SQL Server 2025 ships Cumulative Update 7 with 10 fixes, bringing reliability, security, and JSON improvements across the engine and Analysis Services. It also addresses monitoring, linked server, and recovery issues while tightening encryption and vulnerability protections.

    This article describes Cumulative Update (CU7) for Microsoft SQL Server 2025. This update package contains 10 fixes that were issued after the release of SQL Server 2025 Cumulative Update 6. It updates components in the following builds:

    • SQL Server - Product version: 17.0.4065.4, file version: 2025.170.4065.4
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.
    For more information, see the Known issues section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:
    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.
    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.
    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Access violation when you query sys.dm_exec_requests during database recovery

    Queries against sys.dm_exec_requests might raise an access violation and generate a dump file if they run while a database is still recovering. This issue can occur during a database RESTORE operation, during startup recovery, or before an availability group replica finishes coming online.
    The SQL Server error log contains entries that resemble the following text:

    The database '' is marked RESTORING and is in a state that does not allow recovery to be run.
    ***Stack Dump being sent to \SQLDump0215.txt
    SqlDumpExceptionHandler: Process 77 generated fatal exception c0000005 EXCEPTION_ACCESS_VIOLATION. SQL Server is terminating this process.

    BEGIN STACK DUMP:
    07/30/26 07:37:23 spid 77

    Exception Address = 0x7FFDED94970D
    Exception Code = c0000005 EXCEPTION_ACCESS_VIOLATION
    Access Violation occurred reading address 00000000000000F0
    Input Buffer bytes -
    <dbo.sp_YourMonitoringStoredProcedure>

    This issue occurs because of a change that causes internal in-memory structures to be referenced before they're fully initialized.
    Microsoft is aware of this issue and is investigating a fix. Until a fix is available, use one of the following mitigations:

    • Enable trace flag 4696 to opt out of the code change that causes this issue. If you enable this trace flag, monitoring queries that query sys.dm_exec_requests or sys.sysprocesses on secondary replicas might return error 976 or error 978, as they did before you installed this update.
    • Avoid queries against sys.dm_exec_requests for databases that are recovering.
    • Uninstall this update.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    Bug Reference Description Fix area Component Platform 5216512 Fixes an issue in which monitoring queries that use sys.dm_exec_requests or sys.sysprocesses intermittently fail and return Error "976" or Error "978" when they run against a read-intent only secondary replica in an availability group. SQL Server Engine High Availability and Disaster Recovery Windows 5271098 Updates UCS encryption to use the AES-256 algorithm instead of AES-128 if TLS isn't explicitly enabled. SQL Server Engine Universal Communication Stack All 5281735 Fixes a non-yielding scheduler condition that can occur when SQL Server writes a time zone-related error to the error log. SQL Server Engine Programmability All 5290707 Adds a trace flag that lets you enable TLS 1.3 for SQL Server without having to edit the registry. SQL Server Engine Universal Communication Stack Windows 5293307 Strengthens Service Broker dialog encryption by using the AES-256 algorithm. SQL Server Engine Universal Communication Stack Windows 5295512 Adds logical capping to the EDIT_DISTANCE function to prevent overflow errors that an authenticated user could otherwise use to cause a denial-of-service crash. SQL Server Engine Query Execution All 5295713 Fixes an insecure deserialization vulnerability in the Message Queue task by removing support for the legacy BinaryMessageFormatter (2000 format). This change prevents remote code execution from untrusted MSMQ messages. Integration Services Integration Services Windows 5349316 Fixes an issue in which ALTER JSON INDEX REORGANIZE generates a dump file if statistics exist on the internal table of a JSON index. SQL Server Engine Programmability All 5354186 Fixes an issue in which the node parent offset is calculated incorrectly and can cause JSON corruption during a JSON_MODIFY operation. SQL Server Engine Programmability All 5355051 Fixes an issue in which a JSON_MODIFY merge operation can cause corruption and generate a dump file. SQL Server Engine Programmability All Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5096981 - Cumulative Update 7 for SQL Server 2025

    SQL Server 2025 releases Cumulative Update 7, delivering 10 fixes plus security and stability improvements. It addresses query, JSON, linked server, and availability group issues while strengthening encryption and TLS 1.3 support.

    This article describes Cumulative Update (CU7) for Microsoft SQL Server 2025. This update package contains 10 fixes that were issued after the release of SQL Server 2025 Cumulative Update 6. It updates components in the following builds:

    • SQL Server - Product version: 17.0.4065.4, file version: 2025.170.4065.4
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when they're run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.

    For more information, see the "Known issues" section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    Bug Reference - Description - Fix area - Component - Platform

    • 5216512 - Fixes an issue in which monitoring queries that use sys.dm_exec_requests or sys.sysprocesses intermittently fail and return Error "976" or Error "978" when they run against a read-intent only secondary replica in an availability group. - SQL Server Engine - High Availability and Disaster Recovery - Windows
    • 5271098 - Updates UCS encryption to use the AES-256 algorithm instead of AES-128 if TLS isn't explicitly enabled. - SQL Server Engine - Universal Communication Stack - All
    • 5281735 - Fixes a non-yielding scheduler condition that can occur when SQL Server writes a time zone-related error to the error log. - SQL Server Engine - Programmability - All
    • 5290707 - Adds a trace flag that lets you enable TLS 1.3 for SQL Server without having to edit the registry. - SQL Server Engine - Universal Communication Stack - Windows
    • 5293307 - Strengthens Service Broker dialog encryption by using the AES-256 algorithm. - SQL Server Engine - Universal Communication Stack - Windows
    • 5295512 - Adds logical capping to the EDIT_DISTANCE function to prevent overflow errors that an authenticated user could otherwise use to cause a denial-of-service crash. - SQL Server Engine - Query Execution - All
    • 5295713 - Fixes an insecure deserialization vulnerability in the Message Queue task by removing support for the legacy BinaryMessageFormatter (2000 format). This change prevents remote code execution from untrusted MSMQ messages. - Integration Services - Integration Services - Windows
    • 5349316 - Fixes an issue in which ALTER JSON INDEX REORGANIZE generates a dump file if statistics exist on the internal table of a JSON index. - SQL Server Engine - Programmability - All
    • 5354186 - Fixes an issue in which the node parent offset is calculated incorrectly and can cause JSON corruption during a JSON_MODIFY operation. - SQL Server Engine - Programmability - All
    • 5355051 - Fixes an issue in which a JSON_MODIFY merge operation can cause corruption and generate a dump file. - SQL Server Engine - Programmability - All
    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5101346 - Description of the security update for SQL Server 2025 CU6: July 14, 2026

    SQL Server 2025 ships a security update for Windows and Linux that fixes multiple vulnerabilities, including elevation of privilege, remote code execution, and information disclosure issues, while also resolving an MSMQ deserialization risk and other engine fixes.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Release date: July 14, 2026
    Version: 17.0.4060.2

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-47295 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-47296 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-50468 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-54116 - Windows MultiPoint Services Elevation of Privilege Vulnerability
    • CVE-2026-54117 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-54118 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-55002 - Microsoft SQL Server Elevation of Privilege Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.4060.2, file version: 2025.170.4060.2

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.
    

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.
    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    Bug reference - Description - Fix area - Component - Platform

    • 5340799 - This fix resolves an insecure deserialization vulnerability in MessageQueueTask by removing support for the legacy BinaryMessageFormatter (2000 format). MessageQueueTask prevents remote code execution from untrusted Microsoft Message Queuing (MSMQ) messages. - Integration Services - Integration Services - Windows
    • 5340800 - This fix resolves an insecure deserialization vulnerability in MessageQueueTask by restricting SoapFormatter deserialization that uses an allow list binder. The restriction prevents remote code execution (RCE) from untrusted Microsoft Message Queuing (MSMQ) message. - Integration Service - Integration Service - Windows
    • 5266554 - This fix prevents unintended EXECUTE permission inheritance for EXTERNAL MODEL objects if a newly created principal reuses the same ID as a previously existing principal that had this permission. - SQL Server Engine - Metadata - Windows
    • 5332047 - This fix addresses a vulnerability in SQL Server in which vector intrinsics (VECTOR_DISTANCE, VECTOR_NORM, and VECTOR_NORMALIZE) leak sqlservr.exe process memory to low‑privilege, authenticated SQL Server users if the distance metric or norm algorithm is specified as varchar(max). - SQL Server Engine - Programmability - Linux, Windows
    • 5337381 - This fix resolves a memory leak that occurs if the sys.dm_exec_input_buffer dynamic management function (DMF) or the DBCC INPUTBUFFER command is used. - SQL Server Engine - Query Execution - Linux, Windows
    • 5336749 - This fix addresses input validation and sanitization of user input for a parameter that's passed to an internal replication stored procedure by validating and sanitizing the input before the stored procedure uses it. - SQL Server Engine - Replication - Linux, Windows
    • 5263357 - This fix resolves an SQL injection vulnerability in SQL Server in which improper neutralization of special elements in SQL Server commands allows an authenticated attacker to elevate privileges over a network. - SQL Server Engine - SQL Agent - Linux, Windows

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:
    Download the package now

    How to obtain or download the latest cumulative update package for Linux

    To update SQL Server 2025 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command.

    For installation instructions and direct links to the CU package downloads, see the SQL Server 2025 Release Notes.

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 CU release through this SQL Server 2025 CU6 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name - SHA256 hash

    SQLServer2025-KB5101346-x64.exe - 7C11D53C5C4F84176C84A0A578FE8F2F953EE2A4F986D4AAB70A0C4833B1E804

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5101346.

    Information about protection and security

    Protect yourself online: Windows Security support
    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5102333 - Description of the security update for SQL Server 2025 GDR: July 14, 2026

    SQL Server 2025 releases a security update for Windows and Linux that fixes vulnerabilities, improves SSIS password-based encryption with PBKDF2 SHA-256, and addresses issues in MessageQueueTask, vector intrinsics, memory handling, replication input validation, and SQL injection protection.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Release date: July 14, 2026
    Version: 17.0.1125.2

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-47295 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-47296 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-50468 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-54116 - Windows MultiPoint Services Elevation of Privilege Vulnerability
    • ​​​​​​​CVE-2026-54117 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-54118 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-55002 - Microsoft SQL Server Elevation of Privilege Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.1125.2, file version: 2025.170.1125.2

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.
    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    Bug reference 5264018: Upgrades SQL Server Integration Services (SSIS) password-based encryption (EncryptAllWithPassword and EncryptSensitiveWithPassword) to use PBKDF2 with SHA-256 and 100,000 iterations for packages that target SQL Server 2025. Packages that are saved after this update, including packages that are generated by the Import and Export Wizard, require compatible versions of SQL Server Data Tools (SSDT) and SQL Server Management Studio (SSMS) to open. Until Microsoft releases compatible versions, see the SSDT and SSMS release notes. Packages that target SQL Server 2022 and earlier versions aren't affected.

    Bug reference 5295777: This fix resolves an insecure deserialization vulnerability in MessageQueueTask by removing support for the legacy BinaryMessageFormatter (2000 format). MessageQueueTask prevents remote code execution from untrusted Microsoft Message Queuing (MSMQ) messages.

    Bug reference 5298237: This fix resolves an insecure deserialization vulnerability in MessageQueueTask by restricting SoapFormatter deserialization that uses an allow list binder. The restriction prevents remote code execution (RCE) from untrusted Microsoft Message Queuing (MSMQ) message.

    Bug reference 5160132: This fix prevents unintended EXECUTE permission inheritance for EXTERNAL MODEL objects if a newly created principal reuses the same ID as a previously existing principal that had this permission.

    Bug reference 5332063: This fix addresses a vulnerability in SQL Server in which vector intrinsics (VECTOR_DISTANCE, VECTOR_NORM, and VECTOR_NORMALIZE) leak sqlservr.exe process memory to low‑privilege, authenticated SQL Server users if the distance metric or norm algorithm is specified as varchar(max).

    Bug reference 5335508: This fix resolves a memory leak that occurs if the sys.dm_exec_input_buffer dynamic management function (DMF) or the DBCC INPUTBUFFER command is used.

    Bug reference 5336752: This fix addresses input validation and sanitization of user input for a parameter that's passed to an internal replication stored procedure by validating and sanitizing the input before the stored procedure uses it.

    Bug reference 5196011: This fix resolves an SQL injection vulnerability in SQL Server in which improper neutralization of special elements in SQL Server commands allows an authenticated attacker to elevate privileges over a network.

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:
    Download the package now

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 GDR release through this SQL Server 2025 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name: SQLServer2025-KB5091223-x64.exe
    SHA256 hash: 64EB41E9B91EC15BCEA01880B4CDF52B95DF6595E9989C49FBA4AC194AC9880A

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
    For all supported x64-based versions - Download the list of files that are included in security update 5091223.

    Information about protection and security

    Protect yourself online: Windows Security support
    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Jul 15, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5101346 - Description of the security update for SQL Server 2025 CU6: July 14, 2026

    SQL Server 2025 ships a security update that fixes multiple vulnerabilities, including elevation of privilege, remote code execution, information disclosure, and SQL injection issues, while also addressing memory leaks and other engine fixes.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-47295 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-47296 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-50468 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-54116 - Windows MultiPoint Services Elevation of Privilege Vulnerability
    • CVE-2026-54117 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-54118 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-55002 - Microsoft SQL Server Elevation of Privilege Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.4060.2, file version: 2025.170.4060.2

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.
    

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    Bug reference - Description - Fix area - Component - Platform

    • 5340799 - This fix resolves an insecure deserialization vulnerability in MessageQueueTask by removing support for the legacy BinaryMessageFormatter (2000 format). MessageQueueTask prevents remote code execution from untrusted Microsoft Message Queuing (MSMQ) messages. - Integration Services - Integration Services - Windows
    • 5340800 - This fix resolves an insecure deserialization vulnerability in MessageQueueTask by restricting SoapFormatter deserialization that uses an allow list binder. The restriction prevents remote code execution (RCE) from untrusted Microsoft Message Queuing (MSMQ) message. - Integration Service - Integration Service - Windows
    • 5266554 - This fix prevents unintended EXECUTE permission inheritance for EXTERNAL MODEL objects if a newly created principal reuses the same ID as a previously existing principal that had this permission. - SQL Server Engine - Metadata - Windows
    • 5332047 - This fix addresses a vulnerability in SQL Server in which vector intrinsics (VECTOR_DISTANCE, VECTOR_NORM, and VECTOR_NORMALIZE) leak sqlservr.exe process memory to low‑privilege, authenticated SQL Server users if the distance metric or norm algorithm is specified as varchar(max). - SQL Server Engine - Programmability - Linux, Windows
    • 5337381 - This fix resolves a memory leak that occurs if the sys.dm_exec_input_buffer dynamic management function (DMF) or the DBCC INPUTBUFFER command is used. - SQL Server Engine - Query Execution - Linux, Windows
    • 5336749 - This fix addresses input validation and sanitization of user input for a parameter that's passed to an internal replication stored procedure by validating and sanitizing the input before the stored procedure uses it. - SQL Server Engine - Replication - Linux, Windows
    • 5263357 - This fix resolves an SQL injection vulnerability in SQL Server in which improper neutralization of special elements in SQL Server commands allows an authenticated attacker to elevate privileges over a network. - SQL Server Engine - SQL Agent - Linux, Windows

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to the Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:

    Download the package now

    How to obtain or download the latest cumulative update package for Linux

    To update SQL Server 2025 on Linux to the latest CU, you must first have the Cumulative Update repository configured. Then, update your SQL Server packages by using the appropriate platform-specific update command.

    For installation instructions and direct links to the CU package downloads, see the SQL Server 2025 Release Notes.

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 CU release through this SQL Server 2025 CU6 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name - SHA256 hash

    SQLServer2025-KB5101346-x64.exe - 7C11D53C5C4F84176C84A0A578FE8F2F953EE2A4F986D4AAB70A0C4833B1E804

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5101346.

    Information about protection and security

    Protect yourself online: Windows Security support

    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Jul 14, 2026
    • Date parsed from source:
      Jul 14, 2026
    • First seen by Releasebot:
      Jul 15, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5102333 - Description of the security update for SQL Server 2025 GDR: July 14, 2026

    SQL Server 2025 releases a security update that fixes multiple vulnerabilities, tightens MSMQ deserialization handling, improves SSIS password encryption, and addresses memory leaks, input validation, and permission issues while updating the engine build.

    Applies To

    SQL Server 2025 on Windows (all editions), SQL Server 2025 on Linux (all editions)

    Summary

    This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:

    • CVE-2026-47295 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-47296 - Microsoft SQL Server Elevation of Privilege Vulnerability
    • CVE-2026-50468 - Microsoft SQL Server Information Disclosure Vulnerability
    • CVE-2026-54116 - Windows MultiPoint Services Elevation of Privilege Vulnerability
    • CVE-2026-54117 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-54118 - Microsoft SQL Server Remote Code Execution Vulnerability
    • CVE-2026-55002 - Microsoft SQL Server Elevation of Privilege Vulnerability

    The Microsoft SQL Server components are updated to the following builds in this security update:

    • SQL Server - product version: 17.0.1125.2, file version: 2025.170.1125.2

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Linked server queries that use MSDASQL fail with error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.
    

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists.

    Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#bkmk_NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    Bug reference 5264018

    Upgrades SQL Server Integration Services (SSIS) password-based encryption (EncryptAllWithPassword and EncryptSensitiveWithPassword) to use PBKDF2 with SHA-256 and 100,000 iterations for packages that target SQL Server 2025. Packages that are saved after this update, including packages that are generated by the Import and Export Wizard, require compatible versions of SQL Server Data Tools (SSDT) and SQL Server Management Studio (SSMS) to open. Until Microsoft releases compatible versions, see the SSDT and SSMS release notes. Packages that target SQL Server 2022 and earlier versions aren't affected.

    Bug reference 5295777

    This fix resolves an insecure deserialization vulnerability in MessageQueueTask by removing support for the legacy BinaryMessageFormatter (2000 format). MessageQueueTask prevents remote code execution from untrusted Microsoft Message Queuing (MSMQ) messages.

    Bug reference 5298237

    This fix resolves an insecure deserialization vulnerability in MessageQueueTask by restricting SoapFormatter deserialization that uses an allow list binder. The restriction prevents remote code execution (RCE) from untrusted Microsoft Message Queuing (MSMQ) message.

    Bug reference 5160132

    This fix prevents unintended EXECUTE permission inheritance for EXTERNAL MODEL objects if a newly created principal reuses the same ID as a previously existing principal that had this permission.

    Bug reference 5332063

    This fix addresses a vulnerability in SQL Server in which vector intrinsics (VECTOR_DISTANCE, VECTOR_NORM, and VECTOR_NORMALIZE) leak sqlservr.exe process memory to low‑privilege, authenticated SQL Server users if the distance metric or norm algorithm is specified as varchar(max).

    Bug reference 5335508

    This fix resolves a memory leak that occurs if the sys.dm_exec_input_buffer dynamic management function (DMF) or the DBCC INPUTBUFFER command is used.

    Bug reference 5336752

    This fix addresses input validation and sanitization of user input for a parameter that's passed to an internal replication stored procedure by validating and sanitizing the input before the stored procedure uses it.

    Bug reference 5196011

    This fix resolves an SQL injection vulnerability in SQL Server in which improper neutralization of special elements in SQL Server commands allows an authenticated attacker to elevate privileges over a network.

    How to obtain and install the update

    Method 1: Windows Update

    This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, see Windows Update: FAQ.

    Method 2: Microsoft Update Catalog

    To get the standalone package for this update, go to the Microsoft Update Catalog website.

    Note

    • The detection logic has been updated for this and future security releases that are posted to the Microsoft Update Catalog website. For more information, see Updates to Microsoft Update detection logic for SQL Server servicing.
    • This update is made available through the Microsoft Update Catalog for all servers that are running SQL Server, even if Power BI Report Server is not installed. Installing this security update is optional for computers that do not host Power BI Report Server. For more information, see Download Power BI Report Server.

    Method 3: Microsoft Download Center

    The following file is available for download from the Microsoft Download Center:

    Download the package now

    More information

    Prerequisites

    To apply this update, you must have SQL Server 2025 or any SQL Server 2025 GDR release through this SQL Server 2025 GDR installed.

    Security update deployment information

    For deployment information about this update, see Deployments - Security Update Guide.

    File hash information

    File name: SQLServer2025-KB5091223-x64.exe

    SHA256 hash: 64EB41E9B91EC15BCEA01880B4CDF52B95DF6595E9989C49FBA4AC194AC9880A

    File information

    The English version of this package has the file attributes (or later file attributes) that are listed in the following worksheet. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

    For all supported x64-based versions - Download the list of files that are included in security update 5091223.

    Information about protection and security

    Protect yourself online: Windows Security support

    Learn how we guard against cyber threats: Microsoft Security

    Original source
  • Jun 17, 2026
    • Date parsed from source:
      Jun 17, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Microsoft logo

    SQL Server 2025 by Microsoft

    KB5093421 - Cumulative Update 6 for SQL Server 2025

    SQL Server 2025 ships Cumulative Update 6 with 19 fixes after CU5, plus updates for Database Engine and Analysis Services. It also calls out known issues with SESSION_CONTEXT in parallel plans and MSDASQL linked server queries.

    This article describes Cumulative Update (CU6) for Microsoft SQL Server 2025. This update package contains 19 fixes that were issued after the release of SQL Server 2025 Cumulative Update 5. It updates components in the following builds:

    • SQL Server - Product version: 17.0.4055.5, file version: 2025.170.4055.5
    • Analysis Services - Product version: 17.0.25.223, file version: 2025.170.25.223

    Important

    To help secure SQL Server on Windows, enable encryption with Extended Protection.

    Known issues in this update

    Incorrect behavior of SESSION_CONTEXT in parallel plans

    Queries that use the built-in SESSION_CONTEXT function might return incorrect results or trigger access violation (AV) dump files when run in parallel query plans. This issue occurs because of the manner in which SESSION_CONTEXT interacts with parallel execution threads, particularly if the session is reset for reuse.

    For more information, see the Known issues section in SESSION_CONTEXT.

    Linked server queries that use MSDASQL fail and generate error 7416

    Linked server queries that use the MSDASQL (OLE DB Provider for ODBC Drivers) provider and specify a provider string (@provstr) fail and return the following error message:

    Msg 7416, Level 16
    Access to the remote server is denied because no login-mapping exists.

    A stricter connection validation check in the Database Engine can reject connections for certain linked server configurations that use the MSDASQL provider, even if earlier builds allowed those connections.

    For more information and workarounds, see Linked server queries that use MSDASQL fail with error 7416.

    Improvements and fixes included in this update

    A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists for SQL Server 2025, SQL Server 2022, SQL Server 2019, and SQL Server 2017. Download this Excel file now.

    Note

    Individual entries in the following table can be referenced directly through a bookmark. If you select any bug reference ID in the table, a bookmark tag is added to the URL by using the "#NNNNNNN" format. You can then share this URL with others so that they can jump directly to the desired fix in the table.

    For more information about the bugs that are fixed and enhancements that are included in this cumulative update, see the following table.

    [Table of bug fixes and descriptions omitted for brevity]

    How to obtain or download this CU or the latest CU package

    File information

    Notes for this update

    How to uninstall this update

    References

    • Announcing updates to the SQL Server Incremental Servicing Model (ISM)
    • SQL Server Service Packs are no longer supported starting from SQL Server 2017
    • Determine which version and edition of SQL Server Database Engine is running
    • Servicing models for SQL Server
    • Naming schema and Fix area descriptions for SQL Server software update packages
    • Description of the standard terminology that is used to describe Microsoft software updates
    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.