The current version of Microsoft SQL Server is 17.0.5005.3 CU9 (as of 15/09/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
8.8 high · over the network, with a basic account · CISA deadline was 9 Oct 24
- CVE-2019-1068Microsoft SQL Server Remote Code Execution Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 29 Aug
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Microsoft SQL Server: Mehrere Schwachstellen
WID-SEC-W-2026-3271 · 9 Sept
- Microsoft SQL Server und Power BI: Mehrere Schwachstellen
WID-SEC-W-2026-2327 · 7 Sept
- Microsoft SQL Server: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
WID-SEC-W-2026-3035 · 27 Aug
Microsoft SQL Server at a glance
Microsoft SQL Server is a widely deployed relational database behind countless business applications. Microsoft services it with cumulative updates (CUs) and occasional GDRs (security-only); each version has a defined support lifecycle including mainstream and extended phases.
For admins the routine is CU management and lifecycle planning: apply cumulative updates in a test environment first, then production, minding availability groups/clustering and the documented order. Back up databases before patching. SQL Server holds sensitive data and belongs on the internal network with least-privilege access, TLS and audited logins. Watch the end-of-support dates per version — after that, security fixes stop unless you're on extended support. Keep the edition's licensing in view when planning upgrades.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 17.0 | 17.0.5005.3 CU9 | EOL 6 Jan 36 |
| 16.0 | 16.0.4295.3 CU27 | EOL 11 Jan 33 |
| 13.0-sp3-acp | 13.0.7095.1 Azure Connect pack+GDR | End of Life |
| 13.0-sp3 | 13.0.6500.1 GDR | End of Life |
| 15.0 | 15.0.4490.9 CU32+GDR | EOL 8 Jan 30 |
| 12.0-sp3 | 12.0.6449.1 CU4+GDR | End of Life |
| 13.0-sp2 | 13.0.5893.48 CU17+GDR | End of Life |
| 11.0-sp4 | 11.0.7512.11 GDR | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 17.0.5005.3 CU9 | STABLE | 15/09/2026 | Release notes → |
| 17.0.4085.5 CU8+GDR | STABLE | 08/09/2026 | Release notes → |
| 17.0.4075.5 CU8 | STABLE | 13/08/2026 | Release notes → |
| 17.0.4065.4 CU7 | STABLE | 16/07/2026 | Release notes → |
| 17.0.4055.5 CU6 | STABLE | 17/06/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Microsoft SQL Server?
- Microsoft SQL Server 17.0.5005.3 CU9, released 15/09/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Microsoft SQL Server release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Microsoft SQL Server updates?
- Tick Microsoft SQL Server off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Microsoft SQL Server version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Microsoft SQL Server version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/mssql-server)https://patchletter.com/badge/mssql-server.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).