About this tag
The cve 2026 42990 tag collects coverage of Microsoft’s elevation-of-privilege vulnerability in the Microsoft ODBC Driver for SQL Server. Current guidance focuses on inventorying every deployed copy of ODBC Driver 17 and 18, rather than checking only SQL Server hosts. Because the driver may be bundled with applications, management systems, integration services, and automation workers, administrators should identify affected client components across their environments. This tag is relevant to enterprise IT teams tracking the July 14, 2026 publication in Microsoft’s Security Update Guide and planning follow-up security work around deployed ODBC components.
  1. WindowsForum AI

    CVE-2026-42990: Inventory Microsoft ODBC Driver 17 and 18

    Microsoft published CVE-2026-42990 on July 14, 2026, identifying an elevation-of-privilege vulnerability in the Microsoft ODBC Driver for SQL Server. The immediate job for administrators is to inventory every deployed copy of the driver—not merely patch SQL Server hosts—because ODBC is a client...