Overview

Microsoft released Cumulative Update 8 (CU8) for SQL Server 2025 on 13 August 2026. This update brings the product to build 17.0.4075.5 (file version 2025.170.4075.5) and Analysis Services to 17.0.25.223. It contains 12 fixes applied on top of CU7.

To check your current build, run:

SELECT
    SERVERPROPERTY('ProductVersion')  AS Build,
    SERVERPROPERTY('ProductLevel')    AS Level,
    SERVERPROPERTY('ProductUpdateLevel') AS CULevel;

If Build returns anything lower than 17.0.4075.5, you are not yet on CU8.

Registration is no longer required to download cumulative updates. You can grab the package directly from the Microsoft Download Centre.


What's in This Update

Rather than listing all 12 fixes in order, it is more useful to group them by theme so you can quickly judge what is relevant to your environment.

JSON Engine Fixes (Four Fixes)

This is the heaviest area of work in CU8, with four separate fixes all touching the native json data type introduced in SQL Server 2025.

OPENJSON pattern-matching bug (5425855). If a JSON path expression contained any of the characters %, _, [, or ], OPENJSON would return unexpected rows. These characters are SQL LIKE wildcards, and the engine was incorrectly treating the path as a pattern rather than a literal string. Any code that queries JSON documents with keys containing these characters would silently return wrong data.

DBCC CHECKTABLE assertion on native json computed columns (5434644). Running DBCC CHECKTABLE ... WITH EXTENDED_LOGICAL_CHECKS against a table that had a persisted computed column using the native json type would trigger an assertion failure and generate a dump file. This made routine integrity checks unreliable on affected tables.

JSON_MODIFY array boundary errors (5446188, 5446201, 5446209). Three related fixes address what happens when JSON_MODIFY operates on native json arrays at or beyond 65,535 elements. Appending to an array of exactly 65,535 elements raised errors 13643 and 7102. Passing an array of 65,536 or more elements as the value argument raised error 13643 state 101. Overwriting or deleting a stored array of 65,536 or more elements raised errors 13647 and 13643. These are hard limits that were not being handled gracefully; the fixes introduce correct boundary handling.

In-Memory OLTP (Hekaton) Fix

Stuck Validating transaction with memory-optimised tempdb metadata (5391747). When memory-optimised tempdb metadata is enabled, a Hekaton transaction could get stuck in the Validating state after an internal transaction hit a validation failure during the preparatory phase. A transaction in this state holds resources and cannot be rolled back through normal means, which can block other workloads. This fix corrects the state transition so the transaction is properly cleaned up.

Backup and Restore

VSS backup with WITH MOVE is slow on busy servers (4929794). Restoring a database using Volume Shadow Copy Service with the WITH MOVE option was taking an extremely long time, or timing out entirely, on servers hosting hundreds of databases. The fix addresses the underlying enumeration logic that was scaling poorly with database count. Environments that use VSS-based backup tools (common with third-party backup agents on Windows) and have large numbers of databases should treat this as a meaningful operational fix.

Maintenance and Query Processing

Index rebuild maintenance plan hangs (5197076). An index rebuild maintenance plan could stop responding because of a long-running internal query. This would leave the maintenance job running indefinitely, blocking subsequent scheduled jobs and leaving indexes unfragmented. The fix addresses the query responsible for the hang.

Replication

Multi-subnet failover support for sp_adddistributor (5414824). A new optional parameter @multi_subnet_failover has been added to sp_adddistributor. This allows replication distributors to be configured to support multi-subnet failover scenarios, which is relevant when the distributor or publisher is hosted on an Always On availability group listener that spans subnets.

Setup and Configuration

Incorrect max server memory recommendation during setup (5379749). SQL Server Setup was recommending a maximum server memory value of 128 GB instead of 256 GB for Standard and Standard Developer editions. This could lead to under-configured instances if the recommended value was accepted without review.

mssql-conf collation change hangs on high-CPU Linux systems (5400887). Changing the collation during initial setup via mssql-conf could block indefinitely on Linux systems with a high CPU count. This fix addresses a concurrency issue in the configuration tooling.

PolyBase

gRPC encryption for PolyBase on Linux (5189710). Encryption support has been added for communication between the PolyBase external service and clients using gRPC on Linux. This closes a gap where PolyBase traffic on Linux was not encrypted at the transport layer in this communication path.


Why You Should Apply It

  • Silent wrong results from OPENJSON (5425855): If any application queries JSON documents with keys containing %, _, [, or ], it may be receiving incorrect data right now without any error being raised. This is the highest-priority fix for shops using the native json type.
  • JSON_MODIFY data errors at array boundaries (5446188, 5446201, 5446209): Applications that build or modify large JSON arrays will hit hard errors at 65,535 and 65,536 elements. These are not edge cases in data-intensive pipelines.
  • DBCC CHECKTABLE dumps on json computed columns (5434644): Integrity checks are a core DBA responsibility. A fix that stops them from crashing is not optional.
  • Hekaton transactions stuck in Validating (5391747): A stuck transaction in an In-Memory OLTP workload can cascade into blocking and require a service restart to resolve.
  • VSS backup timeouts on busy servers (4929794): Backup failures are an availability risk. If your backup agent uses VSS and you host many databases, this fix is directly relevant.
  • Index rebuild maintenance plan hangs (5197076): An indefinitely running maintenance job is a silent operational failure that leaves indexes fragmented.
  • PolyBase gRPC encryption on Linux (5189710): If PolyBase is in use on Linux, unencrypted internal service communication is a security gap worth closing.

Known Issues to Be Aware Of

CU8 ships with three documented known issues. Review each before deploying.

SESSION_CONTEXT Incorrect Results in Parallel Plans

Queries using SESSION_CONTEXT() may return incorrect results or generate access violation dump files when executed under a parallel query plan, particularly if the session is being reused from a connection pool. This is a correctness issue. If your application relies on SESSION_CONTEXT() for row-level security, tenant isolation, or any logic that must be correct per-session, you should assess the risk carefully before deploying CU8 in that environment. Microsoft has documented a workaround in the SESSION_CONTEXT known issues page.

MSDASQL Linked Server Queries Fail with Error 7416

Linked server queries using the MSDASQL (OLE DB Provider for ODBC Drivers) provider with a provider string (@provstr) will fail with Msg 7416: Access to the remote server is denied because no login-mapping exists. A stricter connection validation check introduced in the engine rejects configurations that previously worked. If you have linked servers using MSDASQL with a provider string, test this before deploying to production. Microsoft has documented workarounds.

Access Violation Querying sys.dm_exec_requests During Database Recovery

Querying sys.dm_exec_requests while a database is in recovery (during a RESTORE, startup recovery, or before an AG replica comes online) can trigger an access violation and a dump file. This is most likely to affect monitoring scripts or tools that poll this DMV continuously. The risk is highest in environments with frequent restores or AG failovers. Consider temporarily suppressing monitoring queries against this DMV during recovery windows until a fix is available.


Does This Affect You? How to Check

Are you already on CU8?

SELECT SERVERPROPERTY('ProductVersion') AS Build;
-- Target: 17.0.4075.5

Are you using the native json type or OPENJSON / JSON_MODIFY?

-- Find stored procedures, functions, and views referencing JSON functions
SELECT
    OBJECT_SCHEMA_NAME(object_id) AS SchemaName,
    OBJECT_NAME(object_id)        AS ObjectName,
    type_desc
FROM sys.sql_modules
WHERE definition LIKE '%OPENJSON%'
   OR definition LIKE '%JSON_MODIFY%'
   OR definition LIKE '%json%';

Do you have tables with native json columns or persisted computed columns?

SELECT
    OBJECT_SCHEMA_NAME(c.object_id) AS SchemaName,
    OBJECT_NAME(c.object_id)        AS TableName,
    c.name                          AS ColumnName,
    c.is_computed,
    c.is_persisted
FROM sys.columns c
JOIN sys.types t ON c.user_type_id = t.user_type_id
WHERE t.name = 'json';

Are you using In-Memory OLTP with memory-optimised tempdb metadata?

-- Check if memory-optimised tempdb metadata is enabled
SELECT
    configuration_id,
    name,
    value_in_use
FROM sys.configurations
WHERE name = 'tempdb metadata memory-optimized';

-- Check for memory-optimised tables
SELECT
    OBJECT_SCHEMA_NAME(object_id) AS SchemaName,
    name                          AS TableName
FROM sys.tables
WHERE is_memory_optimized = 1;

Do you have linked servers using MSDASQL?

SELECT
    name          AS LinkedServerName,
    provider      AS Provider,
    data_source   AS DataSource
FROM sys.servers
WHERE is_linked = 1
  AND provider = 'MSDASQL';

Do you use SESSION_CONTEXT in your codebase?

SELECT
    OBJECT_SCHEMA_NAME(object_id) AS SchemaName,
    OBJECT_NAME(object_id)        AS ObjectName
FROM sys.sql_modules
WHERE definition LIKE '%SESSION_CONTEXT%';

Do you have many databases and use VSS-based backups?

-- Count of databases on this instance
SELECT COUNT(*) AS DatabaseCount FROM sys.databases;

If this returns a large number (say, over 50) and your backup tooling uses VSS, fix 4929794 is directly relevant.

Are you running PolyBase on Linux?

Check whether the PolyBase service is active on your Linux instance:

SELECT
    name,
    is_enabled
FROM sys.configurations
WHERE name LIKE '%polybase%';

How to Apply

  1. Download the CU8 package from the Microsoft Download Centre. No registration is required.
  2. Apply to a non-production instance first. Run your application test suite and check for the MSDASQL linked server issue and SESSION_CONTEXT behaviour before touching production.
  3. Back up all databases before patching, including system databases.
  4. Plan for a service restart. Cumulative updates require a SQL Server service restart. Schedule a maintenance window and notify application teams.
  5. For Always On AG environments, patch the secondary replicas first, fail over, then patch the former primary. This minimises downtime.
  6. Verify the build after patching:
SELECT
    SERVERPROPERTY('ProductVersion')     AS Build,
    SERVERPROPERTY('ProductLevel')       AS Level,
    SERVERPROPERTY('ProductUpdateLevel') AS CULevel;
-- Expected: 17.0.4075.5 / RTM / CU8
  1. Review the known issues for SESSION_CONTEXT and MSDASQL before signing off on production deployment.

DBA Services Recommendation

For our managed clients, cumulative update assessment and deployment is handled as part of our proactive patching service. We review each CU against your specific workload, flag relevant fixes and known issues, and schedule patching within your agreed maintenance windows. If you are managing SQL Server 2025 independently and would like a second opinion on your patching posture, get in touch with the DBA Services team.