CVE-2026-40370Patch(microsoft / sql_server_2016)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft sql_server_2016 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-610

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sql_server_2016
  • sql_server_2017
  • sql_server_2019
  • sql_server_2022

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-17); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
sql_server_2016sql_server_2017sql_server_2019sql_server_2022sql_server_2025

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-17: 2Mentions · 2026-05-18: 1Mentions · 2026-06-26: 1Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-05-17: 2Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-17: 1Technical Details · 2026-05-18: 105-1405-1505-1705-1806-26
Signal classification3 categories
Patch
466.7%
Active Exploitation
116.7%
Disclosure
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-141
Active Exploitation1
2026-05-151
Disclosure1
2026-05-172
Patch2
2026-05-181
Patch1
2026-06-261
Patch1
Full discourse6 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨تحديثات مايكروسوفت لشهر مايو 2026 قفلت مجموعه من الثغرات الخطيرة على المستخدمين العاديين و المنظمات ملخص الثغرات المهمه من وجهه نظري 📍CVE-2026-41089 في Windows Netlogon التقييم: 9.8 ثغرة RCE قبل المصادقة في Netlogon. خطورتها عالية جداً لأنها تسهل استهداف Domain Controllers، وقد تسمح بتنفيذ كود بصلاحيات عالية بدون حساب مسبق إذا توفرت شروط الاستغلال. هذي اهم ثغره ولازم تعطيها اولولية حالياً 📍CVE-2026-41096 في Windows DNS Client التقييم: 9.8 ثغرة Heap-based buffer overflow في dnsapi.dll. المهاجم قد يستغلها عبر استجابة لطلب DNS خبيث لتنفيذ كود عبر الشبكة. السيناريو الأخطر يظهر إذا قدر يتحكم في مسار DNS أو يستخدم DNS server خبيث أو هجمات Man-in-the-Middle 📍CVE-2026-42898 في Dynamics 365 On-Premises التقييم: 9.9 ثغرة RCE في Dynamics 365 On-Premises خلل في التحكم بعملية توليد الكود داخل Microsoft Dynamics 365 On-Premises يسمح لمهاجم مصادق بتنفيذ كود عبر الشبكة. 📍CVE-2026-40364 في Microsoft Word التقييم: 8.4 ثغرة RCE في Word. الخطر أنها قد تُستغل عند فتح أو معاينة ملف خبيث عبر Preview Pane في بعض السيناريوهات. انتبه ياصديقي لا تركز على نظام التشغيل فقط وتنسى Office. مرفق واحد قد يكون بداية الاختراق 📍CVE-2026-35439 وCVE-2026-40365 في SharePoint Server التقييم: 8.8 ثغرات RCE في SharePoint Server. SharePoint غالباً يحتوي ملفات داخلية، صلاحيات كبيرة ، وربط مع Active Directory. استغلاله قد يعطي المهاجم فرصة للوصول للشبكة الداخلية ويفتح باب للتنقل في الشبكه ايضا. 📍CVE-2026-40370 في SQL Server التقييم: 8.8 ثغرة RCE في SQL Server، لكنها تتطلب صلاحيات منخفضة. الخطر يرتفع إذا كان الخادم مكشوفاً على الانترنت أو إذا حصل المهاجم على حساب محدود. 📍CVE-2026-40415 في Windows TCP/IP التقييم: 8.1 ثغرة RCE في Network Stack نفسه. الخطورة أنها لا تعتمد على ملف Word أو Excel أو رابط تصيد. الاستغلال يتم من خلال الشبكة من خلال حزم مصممة بطريقة معينة. 📍CVE-2026-34332 في Windows Kernel-Mode Driver التقييم: 8.0 ثغرة RCE في Kernel-Mode Driver. عالية الخطورة لأنها مرتبطة طبقة حساسة من النظام. 📍CVE-2026-40359 في Excel التقييم: 7.8 ثغرة RCE في Excel. فتح أو معاينة ملف Excel خبيث قد يؤدي إلى تنفيذ كود على جهاز الضحية. هذا النوع من الثغرات مهم لأن ملفات Office ما زالت من أكثر أدوات الهجوم استخداماً داخل المؤسسات. 📍CVE-2026-34342 في Windows Print Spooler التقييم: 7.0 ثغرة Elevation of Privilege. ليست PrintNightmare جديدة، لكنها تذكرنا أن Print Spooler ما زال سطح هجوم مهم بعد الاختراق الأولي. إذا الخدمة غير مطلوبة على بعض الخوادم، عطّلها. وإذا مطلوبة، حدثها وراقب استخدامها

    Post summary

    The post catalogs several newly disclosed CVEs with high severity scores, providing technical details about each vulnerability but not mentioning exploits, patches, or active exploitation.

    03125912.7K
    50.0K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Microsoft SQL Server (CVE-2026-40370) https://vuldb.com/vuln/363184/cti

    Post summary

    The post reports increased actor activity against Microsoft SQL Server CVE-2026-40370, suggesting potential exploitation but provides no technical details or mitigations.

    0101079
    2.2K followersView on X
  • Merge News@mergenewsapp
    Patch

    AWS RDS Custom for SQL Server gets latest security updates (CUs & GDRs) via Console/SDK/CLI, addressing vulnerabilities like CVE-2026-40370. #aws #rdscustom #sqlserver #securityupdates

    Post summary

    AWS RDS Custom for SQL Server is being updated with the latest CUs & GDRs via Console/SDK/CLI to address vulnerabilities such as CVE-2026-40370, with no PoC, exploit, or active exploitation mentioned.

    0000039
    21 followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    SQL Server 2025 RTM CU4 corrige une faille de déni de service active. #CVE-2026-40370 Patch disponible sur Microsoft Download Center et Update Catalog. Inclut tous les correctifs cumulatifs précédents. Priorité : appliquer KB5089899 sur toute instance SQL Server 2025 exposée sans délai. https://techcommunity.microsoft.com/t5/sql-server-blog/security-update-for-sql-server-2025-rtm-cu4/ba-p/4519134

    Post summary

    Microsoft announced the release of patch KB5089899 to fix CVE‑2026‑40370, a denial‑of‑service vulnerability in SQL Server 2025, and urged immediate application of the update.

    0000068
    24 followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    SQL Server 2019 RTM : patch GDR disponible, une faille DoS corrigée. #CVE-2026-40370 Si votre instance tourne encore en RTM sans CU, ce correctif est votre filet de sécurité minimum. Un déni de service sur le moteur SQL, c'est une prod à terre. Appliquez KB5090408. Pas demain. https://techcommunity.microsoft.com/t5/sql-server-blog/security-update-for-sql-server-2019-rtm/ba-p/4519139

    Post summary

    The post announces a patch (KB5090408) that fixes a DoS vulnerability (CVE-2026-40370) in SQL Server 2019 RTM, urging users to apply it promptly.

    0000046
    24 followersView on X
  • Doctor Kloud@doctorkloud
    Patch

    SQL Server 2017 RTM reçoit un correctif GDR pour une faille DoS référencée #CVE-2026-40370. Un déni de service sur un moteur de base de données en production, c'est une interruption directe des applications métier. KB5090347 couvre aussi tous les correctifs sécurité antérieurs. Patch disponible sur le Microsoft Download Center et le Microsoft Update Catalog. https://techcommunity.microsoft.com/t5/sql-server-blog/security-update-for-sql-server-2017-rtm/ba-p/4519141

    Post summary

    Microsoft released a patch (KB5090347) for CVE-2026-40370, a denial‑of‑service flaw in SQL Server 2017 RTM, with download links provided.

    0000049
    24 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsql_server_2016--x64
Appmicrosoftsql_server_2017--x64
Appmicrosoftsql_server_2019--x64
Appmicrosoftsql_server_2022--x64
Appmicrosoftsql_server_2025--x64

Explore more