Patch tracker / KB5089899
KB5089899
Microsoft security update released 2026-05-12. Fixes 1 CVE.
High
Download KB5089899
Get the official update for KB5089899. The download and file size for each supported product are on the Microsoft Update Catalog page.
Update summary
Released
2026-05-12
CVEs fixed
1
Max CVSS
8.8
Severity
High
Exploitation and severity
Fixes 1 CVE. Most severe CVSS 8.8 (High). EPSS exploit probability up to <1%.
Among the lower half of tracked Microsoft updates by EPSS exploit probability.
What to do
Moderate priority: schedule it in your normal patch cycle. Senserva flags whether KB5089899 is missing on your devices.
CVEs fixed by this update
Affected products
- Microsoft SQL Server 2017 for x64-based Systems (GDR)
- Microsoft SQL Server 2022 for x64-based Systems (CU 24)
- Microsoft SQL Server 2025 for x64-based Systems (CU4)
See this and every Microsoft update ranked by real-world risk on the Microsoft Patch Tracker.