Back to search

Microsoft

SQL Server

See the latest tracked release, confirm when it was published, and subscribe for update emails.

Current version
Last checked: yesterday

GDR (15.0.2165.1)

Release date
April 14, 2026
CVE status
3 visible CVEs

Source

Vendor Release Information

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
GDR (15.0.2165.1) 2026-04-14 Release Notes
GDR (15.0.2160.4) 2026-03-10 Release Notes

Vulnerability tracking

Review curated CVEs for this product and see whether the current version is marked affected. Only CVEs with a CVSS score of 7.0 or higher and published in the last 90 days are shown.

CVE Severity Published Status Summary
CVE-2026-26116 HIGH (8.8) 2026-03-10 Current versionnot affected

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected versions
  • From (including) 15.0.2000.5 - Up to (excluding) 15.0.2160.4
  • From (including) 15.0.4003.23 - Up to (excluding) 15.0.4460.4
CVE-2026-26115 HIGH (8.8) 2026-03-10 Current versionnot affected

Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected versions
  • From (including) 15.0.2000.5 - Up to (excluding) 15.0.2160.4
  • From (including) 15.0.4003.23 - Up to (excluding) 15.0.4460.4
CVE-2026-21262 HIGH (8.8) 2026-03-10 Current versionnot affected

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Affected versions
  • From (including) 15.0.2000.5 - Up to (excluding) 15.0.2160.4
  • From (including) 15.0.4003.23 - Up to (excluding) 15.4460.4