Views
7

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5089900 updates SQL Server 2022 CU24 GDR to address vulnerabilities, including CVE-2026-40370. It also fixes an XML external entity issue in the Web Service Task and updates the engine to build 16.0.4252.3.

Update Details

Security

  • Fixes CVE-2026-40370, a SQL Server remote code execution vulnerability.
  • Addresses an XML external entity (XXE) vulnerability in the Web Service Task that could allow arbitrary file reads or denial of service.

Known Issues

  • Linked server queries that use MSDASQL with a provider string (@provstr) can fail with error 7416: "Access to the remote server is denied because no login-mapping exists."
  • A stricter Database Engine connection validation check can reject some linked server configurations that use the MSDASQL provider.

Hints

  • Prerequisite: SQL Server 2022 or any SQL Server 2022 CU release through this SQL Server 2022 CU24 GDR must already be installed.
  • If you install a language pack after installing this update, reinstall the update.
  • The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
  • For Linux, first configure the Cumulative Update repository, then update SQL Server packages using the platform-specific command.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2022

Version: 16.0.4252.3

Vendor release date: May 12, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026