Patch tracker / Products / Microsoft SQL Server 2022 (CU 24)

Microsoft SQL Server 2022 (CU 24): vulnerabilities and security updates

Every CVE affecting Microsoft SQL Server 2022 (CU 24) and the Microsoft update (KB) that fixes it, ranked by real-world risk. Actively exploited (CISA KEV) first, then EPSS exploit probability, on top of CVSS severity.

CVEs
4
Updates (KBs)
20
Actively exploited (KEV)
0
Critical Severity
0

CVEs affecting Microsoft SQL Server 2022 (CU 24)

CVESeverityCVSSEPSSStatus
CVE-2026-33120High8.80.7%-
CVE-2026-40370High8.80.6%-
CVE-2026-32167Medium6.70.7%-
CVE-2026-32176Medium6.70.7%-

Updates (KBs) for Microsoft SQL Server 2022 (CU 24)

UpdateReleasedSeverityCVSSEPSSCVEsStatus
KB50848152026-04-14High8.80.7%3-
KB50892702026-05-12High8.80.6%1-
KB50892712026-05-12High8.80.6%1-
KB50898992026-05-12High8.80.6%1-
KB50899002026-05-12High8.80.6%1-
KB50903472026-05-12High8.80.6%1-
KB50903542026-05-12High8.80.6%1-
KB50904072026-05-12High8.80.6%1-
KB50904082026-05-12High8.80.6%1-
KB50911582026-05-12High8.80.6%1-
KB50912232026-05-12High8.80.6%1-
KB50832452026-04-14Medium6.70.3%2-
KB50832522026-04-14Medium6.70.3%2-
KB50848142026-04-14Medium6.70.3%2-
KB50848162026-04-14Medium6.70.3%2-
KB50848172026-04-14Medium6.70.3%2-
KB50848182026-04-14Medium6.70.3%2-
KB50848192026-04-14Medium6.70.3%2-
KB50848202026-04-14Medium6.70.3%2-
KB50848212026-04-14Medium6.70.3%2-

Ranked across all products on the Microsoft patch tracker and the CVE and vulnerability management reference. Browse every product: product index.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.