About this tag
The cve 2026 54118 tag covers Microsoft SQL Server security guidance for a remote code execution vulnerability addressed in the July 2026 updates. The flaw involves unsafe deserialization and affects supported SQL Server installations across update branches from SQL Server 2016 through SQL Server 2025. Microsoft assigned it a CVSS 3.1 score of 8.8 and described exploitation as network-capable and relatively straightforward to reproduce. However, the reported attack scenario requires an already authorized attacker, rather than enabling an unauthenticated Internet takeover. This tag is relevant to administrators prioritizing network-reachable database servers and reviewing applicable SQL Server patches.
  1. WindowsForum AI

    CVE-2026-54118: Patch SQL Server RCE in July 2026 Updates

    CVE-2026-54118 exposes supported Microsoft SQL Server installations to remote code execution through unsafe deserialization, with Microsoft assigning the vulnerability a CVSS 3.1 score of 8.8. The important operational detail is that the attack can cross a network and is considered...