NCSC-2026-0232 [1.00] [M/H] Vulnerabilities fixed in Microsoft SQL Server
Microsoft has fixed vulnerabilities in various components of SQL Server. An attacker can exploit the vulnerabilities to grant themselves elevated privileges, execute arbitrary code, and/or gain access to sensitive data.
CSIRTS triage
- What
- Vulnerabilities allow an attacker to grant themselves elevated privileges, execute arbitrary code, and access sensitive data.
- Who is affected
- Users of Microsoft SQL Server.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to severe impacts, although no exploitation has been reported.
- Action
- Update Microsoft SQL Server to the latest version to address the vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SQL Server
Get an email when a new SQL Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0232
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-472960.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Moderate exploitation riskCVE-2026-541171.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all scored CVEs.
- Moderate exploitation riskCVE-2026-541181.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all scored CVEs.
- Low exploitation riskCVE-2026-550020.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-472950.92% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all scored CVEs.
- Low exploitation riskCVE-2026-504680.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-541160.95% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all scored CVEs.
- Low exploitation riskCVE-2026-566420.87% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all scored CVEs.
- Low exploitation riskCVE-2026-586470.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-47296 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54117 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54118 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55002 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47295 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50468 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54116 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56642 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58647 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft SQL Server and Power BI: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure (July 15, 2026)cert-fr-avis
- highCVE-2026-56642: Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker t…nvd
- mediumCVE-2026-54116: Access of resource using incompatible type ('type confusion') in SQL Server allows an authoriz…nvd
- mediumCVE-2026-50468: Buffer over-read in SQL Server allows an authorized attacker to disclose information over a ne…nvd
- highCVE-2026-47295: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Se…nvd
- highCVE-2026-58647: Improper neutralization of input during web page generation ('cross-site scripting') in Power …nvd
- highCVE-2026-55002: External control of file name or path in SQL Server allows an authorized attacker to elevate p…nvd
- highCVE-2026-54118: Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code …nvd
- highCVE-2026-54117: Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code …nvd
- highCVE-2026-47296: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Se…nvd
Recent advisories for Microsoft SQL Server
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft SQL Server and Power BI: Multiple vulnerabilitiescert-bund · 2026-07-15
- mediumCVE-2026-54116: Microsoft SQL Server Information Disclosure Vulnerabilitymsrc · 2026-07-14
- highCVE-2026-47296: Microsoft SQL Server Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
- highCVE-2026-55002: Microsoft SQL Server Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
- highCVE-2026-54118: Microsoft SQL Server Remote Code Execution Vulnerabilitymsrc · 2026-07-14
- mediumCVE-2026-50468: Microsoft SQL Server Information Disclosure Vulnerabilitymsrc · 2026-07-14
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30