Views
6

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5090407 updates SQL Server 2019 CU32 to build 15.0.4470.1 and fixes CVE-2026-40370, a remote code execution vulnerability. It also addresses an XML external entity issue in the Web Service Task.

Update Details

Security

  • CVE-2026-40370 - SQL Server Remote Code Execution Vulnerability
  • Fixes an XML external entity (XXE) vulnerability in the Web Service Task that could allow arbitrary file reads or denial of service.

Known Issues

  • Linked server queries that use MSDASQL with a provider string can fail with error 7416 because stricter connection validation may reject some linked server configurations.

Hints

  • Applies to SQL Server 2019 on Windows and SQL Server 2019 on Linux.
  • To apply this update, SQL Server 2019 or any SQL Server 2019 CU release through CU32 GDR must already be installed.
  • If you install a language pack after installing this update, you must reinstall the update.
  • For Linux, the Cumulative Update repository must be configured before updating to the latest CU.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2019

Version: 15.0.4470.1

Vendor release date: May 12, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026