Views
8

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

KB5091158 is a security update for SQL Server 2022 GDR that fixes vulnerabilities, including CVE-2026-40370. It updates SQL Server 2022 to build 16.0.1180.1 and includes a fix for an XML external entity issue in Integration Services.

Update Details

Security

  • Fixes CVE-2026-40370, a SQL Server remote code execution vulnerability.
  • Addresses an XML external entity (XXE) vulnerability in the Web Service Task that could allow arbitrary file reads or a denial-of-service attack.

Known Issues

  • Linked server queries that use MSDASQL with a provider string (@provstr) can fail with error 7416: 'Access to the remote server is denied because no login-mapping exists.'
  • A stricter Database Engine connection validation check can reject some linked server configurations that use MSDASQL, even if earlier builds allowed them.

Hints

  • Prerequisite: SQL Server 2022 or any SQL Server 2022 GDR release through this GDR must already be installed.
  • If you install a language pack after installing this update, you must reinstall the update.
  • The update is available through Windows Update, Microsoft Update Catalog, and Microsoft Download Center.
  • Installing this security update is optional for computers that do not host Microsoft SQL Server Reporting Services.

Links

Product Information

Vendor: Microsoft

Product: SQL Server

Product type: Software

Variant: SQL Server 2022

Version: 16.0.1180.1

Vendor release date: May 12, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 16, 2026