Views
7

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5090408 updates SQL Server 2019 to build 15.0.2170.1 and addresses CVE-2026-40370, a remote code execution vulnerability. It also fixes an XML external entity issue in the Web Service Task and notes a linked server MSDASQL error 7416 limitation.

Update Details

Security

  • CVE-2026-40370 - SQL Server Remote Code Execution Vulnerability
  • Fixes an XML external entity (XXE) vulnerability in the Web Service Task that could allow arbitrary file read or denial-of-service.

Bug Fixes

  • Fixes an XML external entity (XXE) vulnerability in the Web Service Task.

Known Issues

  • Linked server queries that use MSDASQL with a provider string (@provstr) can fail with error 7416: 'Access to the remote server is denied because no login-mapping exists.'
  • A stricter Database Engine connection validation check can reject some linked server configurations that use the MSDASQL provider.

Hints

  • Install any required language packs before applying this update; otherwise, the update must be reinstalled after adding language packs.
  • The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
  • Prerequisite: SQL Server 2019 or any SQL Server 2019 GDR release through this GDR must already be installed.
  • Installing this security update is optional for computers that do not host Microsoft SQL Server Reporting Services.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2019

Version: 15.0.2170.1

Vendor release date: May 12, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026