Patch tracker / Products / Microsoft SQL Server 2022 (GDR)

Microsoft SQL Server 2022 (GDR): vulnerabilities and security updates

Every CVE affecting Microsoft SQL Server 2022 (GDR) and the Microsoft update (KB) that fixes it, ranked by real-world risk. Actively exploited (CISA KEV) first, then EPSS exploit probability, on top of CVSS severity.

CVEs
5
Updates (KBs)
9
Actively exploited (KEV)
0
Critical Severity
0

CVEs affecting Microsoft SQL Server 2022 (GDR)

CVESeverityCVSSEPSSStatus
CVE-2025-49717High8.511%-
CVE-2025-49719High7.511%-
CVE-2025-49718High7.511%-
CVE-2024-37334High8.81.8%-
CVE-2026-20803High7.21.3%-

Updates (KBs) for Microsoft SQL Server 2022 (GDR)

UpdateReleasedSeverityCVSSEPSSCVEsStatus
KB50587122025-07-08High8.511%3-
KB50587132025-07-08High8.511%3-
KB50587212025-07-08High8.511%3-
KB50587222025-07-08High8.511%3-
KB50407112024-07-09High8.81.6%1-
KB50407122024-07-09High8.81.6%1-
KB50729362026-01-13High7.21.3%1-
KB50730312026-01-13High7.21.3%1-
KB50731772026-01-13High7.21.3%1-

Ranked across all products on the Microsoft patch tracker and the CVE and vulnerability management reference. Browse every product: product index.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.