SQL 2016 Azure Connect Feature Pack
by Microsoft
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-49043 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | ||
| CVE-2024-49021 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2025-49719 | Hig | 0.50 | 7.5 | 0.10 | Jul 8, 2025 | Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-37342 | Hig | 0.46 | 7.1 | 0.02 | Sep 10, 2024 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | ||
| CVE-2025-47997 | Med | 0.42 | 6.5 | 0.01 | Sep 9, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-26115 | 0.00 | — | 0.01 | Mar 10, 2026 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | |||
| CVE-2026-21262 | 0.00 | — | 0.02 | Mar 10, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. |
- risk 0.51cvss 7.8epss 0.01
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.50cvss 7.5epss 0.10
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
- risk 0.46cvss 7.1epss 0.02
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
- CVE-2026-26115Mar 10, 2026risk 0.00cvss —epss 0.01
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-21262Mar 10, 2026risk 0.00cvss —epss 0.02
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Page 3 of 3