Overview

Microsoft released Cumulative Update 27 for SQL Server 2022 on 15 September 2026. This update brings the build number to 16.0.4295.3 and contains 41 fixes applied on top of CU26. It covers the SQL Server Engine, Analysis Services, and associated tooling across Windows and Linux platforms.

If your current build is lower than 16.0.4295.3, this update applies to you. You can check your current version with:

SELECT
    SERVERPROPERTY('ProductVersion') AS Build,
    SERVERPROPERTY('ProductLevel')   AS Level,
    SERVERPROPERTY('ProductUpdateLevel') AS CULevel;

The update is available directly from the Microsoft Download Centre without registration. Analysis Services is also updated, reaching product version 16.0.43.252.

This is a substantial release. The volume of security-related fixes in particular makes it one worth prioritising rather than deferring.


What's in This Update

Security Hardening (the dominant theme)

The single largest category in CU27 is security. A significant number of fixes address memory safety, input validation, and privilege boundaries across multiple components.

Query Optimiser and memory disclosure - Three separate fixes (5505598, 5506056, 5506116) address improper input validation in the Query Optimiser that could allow an authenticated user to read in-memory information or cause dump file generation. These are not remote code execution issues, but they are real information disclosure risks in multi-tenant or shared environments.

Extended Events - Two fixes (5498913, 5499855) address memory corruption from insufficient validation in Extended Events, and information disclosure or denial-of-service risks when the engine reads a specially crafted .xel file. If you use XEvent sessions or process trace files from external sources, these are directly relevant.

XML handling - Three fixes (5495398, 5495725, 5499869) address issues in XML processing. A large OPTION (USE PLAN) hint could trigger an access violation and crash the process. A specially crafted XML format file passed through OPENROWSET(BULK ...) or BULK INSERT could cause an integer overflow and hang or crash the server. DTD attribute list handling for the xml data type also received a correctness fix.

Enclave and Always Encrypted - Four fixes (5505127, 5505432, 5505445, 5505476) harden the enclave code path used by Always Encrypted with secure enclaves. These cover arbitrary memory reads during class ID lookup, missing bounds validation on attestation fields parsed by sys.sp_describe_parameter_encryption, improved OSF deserialization, and buffer length validation. If you use Always Encrypted with VBS or SGX enclaves, these fixes are directly applicable.

Microsoft Entra authentication - Fix 5462844 addresses a security vulnerability in the handling of sign-in requests using Microsoft Entra (formerly Azure AD) authentication. No further detail is disclosed in the KB, which is typical for security fixes that are under coordinated disclosure.

CLR integration - Fix 5529156 addresses an improper field offset validation in the SqlDataRecord.SetBytes API for sql_variant values that can cause an out-of-bounds heap write when CLR integration is enabled.

SQL Server Agent and WMI provider - Fixes 5442243, 5456077, 5459626, and 5481778 collectively improve security validation when SQL Server Agent loads task agent components, improve reliability when Agent processes certain input, fix incorrect handling of malformed input in the WMI provider, and address further Agent reliability issues. These are relevant to any instance running Agent jobs.

Managed backup stored procedures - Fix 5383380 addresses a vulnerability in managed_backup.sp_get_encryption_option and managed_backup.sp_do_backup. If you use SQL Server Managed Backup to Azure, this fix is specifically called out as requiring the standard servicing update.

Replication - Fixes 5529339, 5529351, 5529363, 5529375, and 5529387 improve the security and reliability of internal replication data processing, text handling in merge replication, general replication operation validation, and queued updating subscriptions in transactional replication.

PolyBase - Fix 5487409 improves validation of responses from S3-compatible external storage endpoints. Fix 5494968 closes a raw TCP listener that was being opened unnecessarily for DW Engine and DMS channels when PolyBase services were started with modified command-line parameters.

Data Integrity and Corruption Prevention

Fix 2796714 addresses a rare but serious issue: rolling back a user transaction could cause database corruption reported by DBCC CHECKDB as Page Free Space (PFS) page errors, but only on instances where Accelerated Database Recovery (ADR) is disabled. ADR is off by default in SQL Server 2022 unless you have explicitly enabled it. If you are running without ADR and experience unexpected transaction rollbacks, this fix is worth prioritising.

In-Memory OLTP (Natively Compiled Procedures)

Three fixes (5482772, 5482827, 5482833) address memory safety issues in natively compiled stored procedures. These cover buffer over-reads in SUBSTRING when processing malformed DBCS varchar values, access violations when converting or truncating nvarchar values containing ideographic variation sequences under _VSS collations, and heap buffer overwrites when streaming nvarchar(max) data under _VSS collations with small TDS packet sizes. If you use In-Memory OLTP with natively compiled procedures and handle East Asian character data, these are directly relevant.

High Availability and Disaster Recovery

Fix 5478465 resolves an issue where a secondary replica could fail to join an availability group with a 64-character name and a cluster type of NONE or EXTERNAL. This is a specific edge case but one that would be completely blocking if encountered.

Fix 5558709 fixes an upgrade hang from SQL Server 2019 to SQL Server 2022 that occurs during the replicated_model database upgrade phase on instances hosting one or more contained availability groups. If you are mid-migration from 2019 to 2022, this is important to know before you start.

Backup and Restore

Fix 4929823 addresses VSS restores with WITH MOVE taking an excessive amount of time or timing out when the server hosts hundreds of databases. Fix 5434228 improves validation of backup metadata processed by the SQL Server VSS Writer to safely reject malformed or undersized metadata.

Unicode and Internationalisation

Fixes 5126055 and 5473595 address failures when creating database users whose display names contain Kanji or other Unicode characters not supported by the system default code page. This affects both standard user creation and creation from Microsoft Entra ID using WITH OBJECT_ID. Relevant to any environment with Japanese, Chinese, or Korean user accounts.

Query Store

Fix 5529195 improves the handling of Showplan input in Query Store to enhance security and reliability.

Linux

Fix 5421858 addresses a timing-dependent race condition during interrupt delivery while SQL Server on Linux handles exceptions. Relevant only to Linux deployments.


Why You Should Apply It

  • Memory disclosure via Query Optimiser (5505598, 5506056, 5506116): authenticated users can read in-memory data. Relevant to any shared or multi-tenant instance.
  • Extended Events memory corruption and denial of service (5498913, 5499855): malformed XEvent data can corrupt memory or crash the engine.
  • XML processing crashes (5495725, 5499869): crafted query hints or bulk import format files can hang or crash the SQL Server process.
  • Database corruption on transaction rollback (2796714): affects instances with ADR disabled, which is the default configuration.
  • Always Encrypted enclave hardening (5505127, 5505432, 5505445, 5505476): multiple memory safety issues in enclave code.
  • Microsoft Entra authentication vulnerability (5462844): sign-in handling vulnerability, relevant to any instance using Entra authentication.
  • CLR out-of-bounds heap write (5529156): relevant to any instance with CLR integration enabled.
  • Managed backup vulnerability (5383380): specifically called out by Microsoft as requiring the standard servicing update.
  • VSS restore timeout (4929823): operational fix for environments with large numbers of databases.
  • Availability group join failure at 64-character name (5478465): completely blocking if encountered.
  • Upgrade hang from 2019 to 2022 with contained AGs (5558709): blocks in-progress migrations.

Known Issues to Be Aware Of

Microsoft has documented three known issues introduced or present in CU27.

SESSION_CONTEXT Incorrect Results in Parallel Plans

Queries using SESSION_CONTEXT() may return incorrect results or generate access violation dump files when executed under a parallel query plan, particularly if the session is being reused from a connection pool. This is a correctness issue, not just a crash risk. If your application relies on SESSION_CONTEXT() to pass session-scoped values (common in row-level security implementations), test carefully before deploying to production. This issue should be evaluated as a potential blocker if SESSION_CONTEXT() is used in security-sensitive logic.

Linked Server Queries Using MSDASQL Fail with Error 7416

Linked server queries using the MSDASQL (OLE DB Provider for ODBC Drivers) provider with a provider string (@provstr) will fail with Msg 7416, Level 16 - Access to the remote server is denied because no login-mapping exists. This is a regression introduced by stricter connection validation. If you have linked servers configured with MSDASQL and a provider string, test this before deploying. The KB documents workarounds; check the linked article for details.

Access Violation Querying sys.dm_exec_requests During Database Recovery

Querying sys.dm_exec_requests while a database is in recovery (during a RESTORE, startup recovery, or before an AG replica comes online) can trigger an access violation and generate a dump file, terminating the SQL Server process. Monitoring scripts or third-party tools that poll sys.dm_exec_requests continuously are at risk during maintenance windows. Consider pausing such polling during restore or failover operations.


Does This Affect You? How to Check

Build version check

SELECT
    SERVERPROPERTY('ProductVersion') AS CurrentBuild,
    SERVERPROPERTY('ProductLevel')   AS Level;
-- Target build for CU27 is 16.0.4295.3
-- If CurrentBuild < 16.0.4295.3, this update applies

ADR status (relevant to fix 2796714 - PFS corruption)

SELECT name, is_accelerated_database_recovery_on
FROM sys.databases
WHERE is_accelerated_database_recovery_on = 0
  AND database_id > 4;
-- Databases returned here are at risk from the rollback/PFS corruption issue

SESSION_CONTEXT usage (known issue)

SELECT OBJECT_NAME(object_id) AS ObjectName, definition
FROM sys.sql_modules
WHERE definition LIKE '%SESSION_CONTEXT%';
-- Any results mean you should test the known issue before deploying

CLR integration enabled (relevant to fix 5529156)

SELECT name, value_in_use
FROM sys.configurations
WHERE name = 'clr enabled';
-- value_in_use = 1 means CLR is on and the fix applies

Linked servers using MSDASQL (known issue)

SELECT name, provider, provstr
FROM sys.servers
WHERE is_linked = 1
  AND provider = 'MSDASQL'
  AND provstr IS NOT NULL AND provstr <> '';
-- Any results mean you are at risk from the error 7416 known issue

Availability group name length (relevant to fix 5478465)

SELECT name, LEN(name) AS NameLength, automated_backup_preference_desc
FROM sys.availability_groups
WHERE LEN(name) = 64;
-- 64-character AG names with cluster type NONE or EXTERNAL are affected

Always Encrypted with enclaves (relevant to fixes 5505127, 5505432, 5505445, 5505476)

SELECT name, enclave_type_desc
FROM sys.column_master_keys
WHERE enclave_type_desc IS NOT NULL AND enclave_type_desc <> 'NONE';
-- Any results indicate enclave-enabled CMKs are in use

PolyBase in use (relevant to fixes 5487409, 5494968)

SELECT name, value_in_use
FROM sys.configurations
WHERE name = 'polybase enabled';

Managed backup in use (relevant to fix 5383380) - Check whether the managed_backup schema exists in msdb:

SELECT SCHEMA_ID('managed_backup') AS ManagedBackupSchemaID;
-- Non-NULL result means managed backup is configured

Monitoring tools polling sys.dm_exec_requests (known issue) - Review any SQL Agent jobs, monitoring scripts, or third-party tools that query sys.dm_exec_requests on a continuous or near-continuous basis. Pause these during restore operations or AG failovers until Microsoft resolves this known issue.


How to Apply

  1. Test in non-production first. Given the three documented known issues, validate your application against a restored copy of production before scheduling the production rollout.
  2. Back up all databases before applying, including system databases.
  3. Check the known issues against your environment using the queries above. If you use SESSION_CONTEXT() in security logic or have MSDASQL linked servers with provider strings, resolve those concerns before proceeding.
  4. Plan for a service restart. Applying a CU requires restarting the SQL Server service. Schedule a maintenance window with appropriate downtime notification.
  5. Apply to AG secondaries first where possible, fail over, then patch the remaining node.
  6. Verify the build after patching:
SELECT SERVERPROPERTY('ProductVersion') AS Build;
-- Should return 16.0.4295.3
  1. Download directly from the Microsoft Download Centre (no registration required): https://www.microsoft.com/download/details.aspx?familyid=105013

DBA Services Recommendation

For our managed clients, cumulative update assessment and deployment is handled as part of our proactive patching service. We review each CU against your specific environment configuration, run the relevant checks, and schedule patching within your agreed maintenance windows. CU27 contains enough security fixes that we are treating it as a priority release for managed environments. If you are not a managed client and would like assistance assessing or deploying this update, contact the DBA Services team.