KB5077465: Fixes an elevation of privilege vulnerability in the version upgrade process for merge replication.
KB5077465 - Description of the security update for SQL Server 2022 GDR: March 10, 2026
Summary
This security update contains fixes and resolves vulnerabilities. To learn more about the vulnerabilities, see the following security advisories:
- CVE-2026-21262 - SQL Server Elevation of Privilege Vulnerability
- CVE-2026-26115 - SQL Server Elevation of Privilege Vulnerability
The Microsoft SQL Server components are updated to the following builds in this security update:
- SQL Server - product version: 16.0.1170.5, file version: 2022.160.1170.5
Improvements and fixes included in this update
A downloadable Microsoft Excel workbook that contains a summary list of builds, together with their current support lifecycle, is available. The Excel file also contains detailed fix lists. Download this Excel file now.
- 4973068: Fixes an elevation of privilege vulnerability in the version upgrade process for merge replication.
- 4913368: This hotfix blocks the ALTER USER operation if the target login is the system Administrator account.

