Views
6

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5090347 updates SQL Server 2017 to build 14.0.2110.2 and addresses vulnerabilities, including CVE-2026-40370. It also fixes an XML external entity (XXE) issue in the Web Service Task.

Update Details

Security

  • Fixes CVE-2026-40370: SQL Server Remote Code Execution Vulnerability.
  • Addresses an XML external entity (XXE) vulnerability in the Web Service Task that could allow arbitrary file reads or a denial-of-service attack.

Known Issues

  • Linked server queries that use MSDASQL with a provider string (@provstr) can fail with error 7416: 'Access to the remote server is denied because no login-mapping exists.'
  • A stricter connection validation check in the Database Engine can reject some linked server configurations that use the MSDASQL provider.

Hints

  • Prerequisite: SQL Server 2017 or any SQL Server 2017 GDR release through this GDR must already be installed.
  • If you install a language pack after installing this update, you must reinstall the update.
  • The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
  • Installing this security update is optional for computers that do not host Microsoft SQL Server Reporting Services.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2017

Version: 14.0.2110.2

Vendor release date: May 12, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026