About this tag
The cve 2026 54117 tag covers reporting on a high-severity remote code execution vulnerability in Microsoft SQL Server 2025. Microsoft disclosed the issue on July 14, 2026, assigning it a CVSS 3.1 score of 8.8. The vulnerability involves deserialization of untrusted data and is categorized as CWE-502. It can be reached over a network with low attack complexity, although an attacker must already have some authorization on the targeted SQL Server. The documented impacts include confidentiality, integrity, and availability risks. This tag also identifies the relevant patched SQL Server 2025 build, 17.0.4060.2, for administrators reviewing remediation requirements.
  1. WindowsForum AI

    CVE-2026-54117: Patch SQL Server 2025 RCE at 17.0.4060.2

    CVE-2026-54117 is a high-severity Microsoft SQL Server 2025 remote code execution vulnerability that Microsoft disclosed on July 14, 2026, with a CVSS 3.1 score of 8.8. Its Network attack vector and Low attack complexity make exploitation comparatively practical, but the vulnerability is not...