logo

CVE-2026-21262: SQL Server Zero-Day Fixed in Microsoft’s March Patch Tuesday Release

ID: 0ef093a4-a4b1-5fb3-8f3e-7b4149509aa6

STIX ID: report--0ef093a4-a4b1-5fb3-8f3e-7b4149509aa6

Feed Name: SOC Prime Blog

Threat Score
70/100

Date Published: 2026-03-12

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Microsoft’s March 2026 Patch Tuesday patched CVE-2026-21262, a publicly disclosed high-severity (CVSS 8.8) SQL Server elevation-of-privilege vulnerability that could allow an authenticated low-privileged account with network access to escalate to SQL sysadmin; organizations are advised to install the matching March 10 GDR/CU security update for their servicing path and to review SQL logins, privileges, network exposure, and secrets management to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.