PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47297 Microsoft CVE debrief

Microsoft SQL Server Remote Code Execution Vulnerability allows an unauthorized attacker to execute code over a network due to deserialization of untrusted data. Affected versions include Microsoft SQL Server 2019 (CU 32), 2019 (GDR), 2022 (CU 26), 2022 (GDR), 2025 (CU8), and 2025 for x64-based Systems (GDR). This vulnerability has a high CVSS score of 8.1, indicating a high severity. Defenders should prioritize patching vulnerable instances, especially those exposed to the internet or in high-risk environments, to prevent potential code execution and unauthorized access. The CVE record and source item provide details on the vulnerability, affected versions, and references to the 4

Vendor
Microsoft
Product
Microsoft SQL Server 2019 (CU 32)
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-10-08
Advisory published
2026-09-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for SQL Server instances, especially those exposed to the internet or in high-risk environments, should assess exposure and prioritize patching.

Why it matters

CVE-2026-47297 is a high-severity vulnerability in Microsoft SQL Server that allows remote code execution. Defenders should prioritize patching vulnerable instances, especially those exposed to the internet or in high-risk environments, to prevent potential code execution and unauthorized access.

  • Potential code execution over the network
  • Unauthorized access to sensitive data
  • Disruption of critical database services
  • Elevation of privileges for attackers

Technical summary

The vulnerability allows an unauthorized attacker to execute code over a network due to deserialization of untrusted data in SQL Server. Affected versions include Microsoft SQL Server 2019 (CU 32), 2019 (GDR), 2022 (CU 26), 2022 (GDR), 2025 (CU8), and 2025 for x64-based Systems (GDR).

Defensive priority

Defenders should prioritize patching vulnerable SQL Server instances, especially those exposed to the internet or in high-risk environments.

Recommended defensive actions

  • Patch vulnerable SQL Server instances
  • Verify and apply vendor-provided updates
  • Restrict network exposure for vulnerable instances
  • Monitor for suspicious activity

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and references to vendor advisories. The vulnerability allows an unauthorized attacker to execute code over a network due to deserialization of untrusted data in SQL Server. Affected versions include Microsoft SQL Server 2019 (CU 32), 2019 (GDR), 2022 (CU 26), 2022 (GDR), 2025 (CU8), and 2025 for x64-based Systems (GDR). The CVE Program record (CVE-2026-47297) and the NIST NVD detail page (CVE-2026-

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47297 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47297

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47297 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47297

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Microsoft SQL Server Remote Code Execution Vulnerability

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/47xxx/CVE-2026-47297.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47297

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.