Microsoft SQL Server SQL Server 2017 Update Version 14.0.3530.2 / 2017.140.3530.2
Views
8
Your rating
Rate update installation process
Log in to rate this update.
Login
Risk factor
No ratings yet. Be the first to rate this update.
Smooth installs
0%
Minor issues
0%
Major issues
0%
AI enhanced content
Update Summary
KB5090354 updates SQL Server 2017 CU31 to 14.0.3530.2 / 2017.140.3530.2 and addresses CVE-2026-40370, a remote code execution vulnerability. It also fixes an XML external entity issue in the Web Service Task.
Update Details
Security
- Fixes CVE-2026-40370: SQL Server Remote Code Execution Vulnerability.
- Addresses an XML external entity (XXE) vulnerability in the Web Service Task that could allow arbitrary file reads from the local file system or a denial-of-service attack.
Known Issues
- Linked server queries that use MSDASQL with a provider string (
@provstr) can fail with error 7416: "Access to the remote server is denied because no login-mapping exists." - A stricter Database Engine connection validation check can reject some linked server configurations that use the MSDASQL provider.
Hints
- If you install a language pack after this update, you must reinstall the update; install required language packs first.
- The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
- The Microsoft Update Catalog detection logic has been updated for this and future SQL Server security releases.
- The update is offered for all SQL Server servers in the Microsoft Update Catalog, even if Reporting Services is not installed; installation is optional for computers that do not host SQL Server Reporting Services.
Product Information
Vendor: Microsoft
Product: SQL Server
Product type: Software
Variant: SQL Server 2017
Version: 14.0.3530.2 / 2017.140.3530.2
Vendor release date: May 12, 2026
Original release notes: View on vendor site
Published on updatealert.io: Aug 16, 2026