CVE-2026-26116 is a high-severity SQL Injection vulnerability impacting Microsoft SQL Server versions 2016, 2017, 2019, 2022, and 2025. Rated 8.8 CVSS, this flaw allows an authorized attacker with low privileges to execute arbitrary SQL commands over a network with low attack complexity, leading to a complete compromise of confidentiality, integrity, and availability through privilege escalation. There is no known public exploit code, active exploitation, or inclusion in CISA's KEV catalog. However, the vulnerability has garnered some community and media attention as part of the March 2026 Patch Tuesday releases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.6300.2, < 13.0.6480.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 13.0.7000.253, < 13.0.7075.5CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2016:*:*:*:*:*:*:x64:* | ||
>= 14.0.1000.169, < 14.0.2100.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 14.0.3006.16, < 14.0.3520.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2017:*:*:*:*:*:*:x64:* | ||
>= 15.0.2000.5, < 15.0.2160.4CPE matchmatch criteria | cpe:2.3:a:microsoft:sql_server_2019:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.