Risk Scores
CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
0.07%
21.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft SQL Server 2025 for x64-based Systems (GDR) | 17.0.1050.2 |
| Microsoft | Microsoft SQL Server 2016 Service Pack 3 (GDR) | 13.0.0 |
| microsoft | sql_server_2017 | 14.0.0, 14.0.0 |
| Microsoft | Microsoft SQL Server 2025 (CU 2) | 17.0.0.0 |
| microsoft | azure_mcp_server_tools_2 | 2.0.0-beta.1, 2.0.0-beta.1, 2.0.0-beta.1 |
| Microsoft | Azure MCP Server Tools 2.0.0 (npm) | 2.0.0-beta.1, 2.0.0-beta.1, 2.0.0-beta.1 |
| microsoft | sql_server_2019 | 15.0.0.0, 15.0.0 |
| microsoft | sql_server_2016 | 13.0.0, 13.0.0 |
| Microsoft | Microsoft SQL Server 2022 for x64-based Systems (CU 23) | 16.0.0.0 |
| Microsoft | Azure MCP Server Tools 1.0.0 (NuGet) | 1.0.0, 1.0.0, 1.0.0 |
| azure | mcp | 2.0.0-beta.1, 1.0.0, 2.0.0-beta.1 |
| Microsoft | Azure MCP Server Tools 1.0.0 (npm) | 1.0.0, 1.0.0, 1.0.0 |
| Microsoft | Azure MCP Server Tools 2.0.0 (PyPi) | 2.0.0-beta.1, 2.0.0-beta.1, 2.0.0-beta.1 |
| Microsoft | Microsoft SQL Server 2019 (GDR) | 15.0.0 |
| Microsoft | Microsoft SQL Server 2017 (GDR) | 14.0.0 |
| microsoft | azure_mcp_server_tools_1 | 1.0.0, 1.0.0, 1.0.0 |
| microsoft | azure_mcp_server | 0, 2.0.0, 2.0.0 |
| microsoft | sql_server_2025 | 17.0.0.0, 17.0.1050.2 |
| Microsoft | Microsoft SQL Server 2019 (CU 32) | 15.0.0.0 |
| microsoft | sql_server_2022 | 16.0.0, 16.0.0.0 |
…and 6 more
Timeline
- Mar 10, 2026 CVE Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 10, 2026 PoC Published
- Mar 11, 2026 EPSS Score
- Mar 11, 2026 PoC Published
- Mar 11, 2026 PoC Published
- Mar 11, 2026 Security Advisory
- Mar 11, 2026 PoC Published
- Mar 11, 2026 PoC Published
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26117 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21262 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23661 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26115 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26121 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23665 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26118 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23664 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26148 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23662 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-26118 advisory
- https://github.com/microsoft/mcp/commit/804ff60293206c4d8e832f772097238561bf2c34 url
- https://github.com/microsoft/mcp package
- https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-1.0.2 url
- https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-2.0.0-beta.17 url