← Back to CVE List
CVE-2026-54117NVD
Vulnerability Summary
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Microsoft Sql Server 2016 >= 13.0.6300.2 and < 13.0.6500.1
- Microsoft Sql Server 2016 >= 13.0.7000.253 and < 13.0.7095.1
- Microsoft Sql Server 2017 >= 14.0.1000.169 and < 14.0.2120.1
- Microsoft Sql Server 2017 >= 14.0.3006.16 and < 14.0.3540.1
- Microsoft Sql Server 2019 >= 15.0.2000.5 and < 15.0.2180.2
- Microsoft Sql Server 2019 >= 15.0.4003.23 and < 15.0.4480.2
- Microsoft Sql Server 2022 >= 16.0.1000.6 and < 16.0.1190.2
- Microsoft Sql Server 2022 >= 16.0.4003.1 and < 16.0.4262.2
- Microsoft Sql Server 2025 >= 17.0.1000.7 and < 17.0.1125.2
- Microsoft Sql Server 2025 >= 17.0.4006.2 and < 17.0.4060.2
- Microsoft Sql Server 2016 13.0.6500.1
- Microsoft Sql Server 2016 13.0.7095.1
- Microsoft Sql Server 2017 14.0.2120.1
- Microsoft Sql Server 2017 14.0.3540.1
- Microsoft Sql Server 2019 15.0.2180.2
- Microsoft Sql Server 2019 15.0.4480.2
- Microsoft Sql Server 2022 16.0.1190.2
- Microsoft Sql Server 2022 16.0.4262.2
- Microsoft Sql Server 2025 17.0.1125.2
- Microsoft Sql Server 2025 17.0.4060.2