Views
5

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5077471 updates SQL Server 2017 CU31 to build 14.0.3520.4 and fixes two elevation of privilege vulnerabilities: CVE-2026-21262 and CVE-2026-26115. It also includes security-related fixes for merge replication upgrade and ALTER USER handling.

Update Details

Security

  • Fixes CVE-2026-21262: SQL Server elevation of privilege vulnerability.
  • Fixes CVE-2026-26115: SQL Server elevation of privilege vulnerability.
  • Fixes an elevation of privilege vulnerability in the version upgrade process for merge replication.
  • Blocks ALTER USER when the target login is the system Administrator account.

Hints

  • Install language packs before applying this update; otherwise, the update must be reinstalled.
  • The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
  • Microsoft Update Catalog detection logic was updated for this and future SQL Server security releases.
  • The update is optional for computers that do not host Microsoft SQL Server Reporting Services.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2017

Version: 14.0.3520.4

Vendor release date: Mar 10, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026