Overview
Microsoft released Cumulative Update 9 (CU9) for SQL Server 2025 on 15 September 2026. This update brings the build to 17.0.5005.3 and contains 44 fixes applied on top of CU8. Analysis Services is also updated, reaching product version 17.0.25.223.
If your server currently reports a build number lower than 17.0.5005.3, you are not yet on CU9. You can check your current build with:
SELECT
SERVERPROPERTY('ProductVersion') AS Build,
SERVERPROPERTY('ProductLevel') AS Level,
SERVERPROPERTY('ProductUpdateLevel') AS CULevel;
Compare the Build value against 17.0.5005.3. Anything lower means CU9 is not yet applied.
The KB article for this release is KB5122048. Registration is no longer required to download cumulative updates.
What's in This Update
With 44 fixes, CU9 is a substantial release. Rather than listing every bug number, the fixes fall into clear themes that help you assess relevance quickly.
Security Hardening (the dominant theme)
The single most striking characteristic of CU9 is the volume of security-related fixes. This is not routine patching - a significant portion of the 44 fixes address memory safety, input validation, and privilege handling across multiple engine subsystems.
Buffer overflows and memory corruption are addressed in several places. A buffer overflow during an authenticated TDS remote procedure call (5314117) could cause the SQL Server process to terminate unexpectedly. The LEFT_SHIFT and RIGHT_SHIFT functions could trigger arithmetic overflow or out-of-bounds memory access with crafted input (5496451). The SUBSTRING function in natively compiled stored procedures could read beyond an allocated buffer when processing malformed DBCS varchar values (5482770). Streaming nvarchar(max) data under a variation selector sensitive collation in natively compiled procedures could cause a heap buffer overwrite (5482831).
Extended Events received two security fixes. Insufficient validation could cause memory corruption (5498355), and reading a specially crafted .xel file could allow information disclosure or a denial of service (5498927). If your environment ingests .xel files from external sources or untrusted systems, this is directly relevant.
XML handling had three fixes. An integer overflow in the XML reader when processing a crafted XML format file through OPENROWSET(BULK ...) or BULK INSERT could cause the process to stop responding (5499864). An extremely large OPTION (USE PLAN) XML declaration could trigger an access violation (5495722). DTD attribute list handling for the xml data type was also corrected (5495464).
Enclave and Always Encrypted components received targeted hardening. A class ID lookup in enclave code was reading arbitrary memory (5486869), bounds validation was added for attestation fields parsed by sys.sp_describe_parameter_encryption (5486988), and buffer length validation in enclave code was improved (5502845).
SQL Server Agent received three separate security and reliability fixes (5442240, 5456076, 5477946), covering task agent component loading, input processing, and general operating conditions.
Microsoft Entra authentication had a vulnerability in sign-in request handling fixed (5462726).
Managed backup stored procedures (managed_backup.sp_get_encryption_option and managed_backup.sp_do_backup) had a vulnerability addressed (5383382).
Query Optimizer received three input validation fixes (5505723, 5506053, 5506113) that prevent authenticated users from disclosing in-memory information or triggering dump file generation.
Replication received a cluster of security and reliability improvements covering internal data protection (5529344), merge replication text handling (5529357), general replication operation validation (5529369), and queued updating subscriptions in transactional replication (5529380, 5529393).
SqlDataRecord.SetBytes for sql_variant values could cause an out-of-bounds heap write when CLR integration is enabled (5529203 covers Showplan input; 5529170 covers the SqlDataRecord API specifically).
High Availability and Availability Groups
One targeted fix addresses a secondary replica failing to join an availability group that has a 64-character name with a cluster type of NONE or EXTERNAL (5479036). If you use AG names at or near the 64-character limit with external or no cluster, this fix is directly applicable.
Replication and Change Event Streaming
Beyond the security improvements, two functional fixes address Change Event Streaming (CES). Event deserialization fails if payloads contain certain characters (5529457), and dump files could occur during serialisation of large object data streamed through CES (5529461). If you are using CES in SQL Server 2025, both of these are worth noting.
Performance Monitoring and SQL OS
The Buffer cache hit ratio performance counter was always showing zero in Performance Monitor (5504681). This is a monitoring reliability issue rather than an engine correctness issue, but it means any alerting or capacity planning based on that counter has been producing misleading data. The fix restores accurate reporting.
Manual soft-NUMA configuration support has been added for the Standard and Standard Developer editions (5514968), which previously required Enterprise edition for this capability.
Security Auditing
The data_sensitivity_information field was not consistently populated in audit records generated by the SCHEMA_OBJECT_ACCESS_GROUP audit action group (5504495). If you rely on sensitivity labels appearing in audit logs for compliance purposes, this fix ensures they are reliably included.
Unicode and Kanji User Creation
Two related fixes address creating database users whose display names contain Kanji or other Unicode characters that the system default code page does not support. One covers standard user creation (5126015) and the other covers creating users from Microsoft Entra ID using the WITH OBJECT_ID option (5473622). Both affect Windows environments where the system code page is not Unicode-aware.
Storage and tempdb
An inconsistency in tempdb space usage reported by sys.dm_db_session_space_usage after DROP or TRUNCATE operations has been corrected (5511027). If you use this DMV for tempdb monitoring or alerting, the reported values were potentially inaccurate.
PolyBase and External Data
Validation of responses from S3-compatible external storage endpoints was improved (5487460). A separate fix addresses a raw TCP listener being opened unnecessarily for DW Engine and DMS channels when PolyBase services start with modified command-line parameters (5494995).
VSS Writer
Validation of backup metadata processed by the SQL Server VSS Writer was improved so that malformed or undersized metadata is rejected safely (5434226).
Why You Should Apply It
- Process termination risk from TDS buffer overflow (5314117): An authenticated RPC call could crash the SQL Server process. This is a high-severity stability and security concern.
- Memory corruption via Extended Events (5498355, 5498927): Crafted .xel files or insufficient XE validation could corrupt memory or disclose information.
- XML BULK INSERT integer overflow (5499864): A crafted XML format file could hang or crash the server.
- Natively compiled procedure memory safety (5482770, 5482825, 5482831): Three separate buffer and heap issues in In-Memory OLTP procedures, any of which could cause crashes or data exposure.
- Enclave arbitrary memory read (5486869): Enclave code was reading from arbitrary memory addresses, a serious security defect for Always Encrypted environments.
- Entra authentication vulnerability (5462726): Sign-in request handling had a security flaw that this fix addresses.
- Query Optimizer information disclosure (5505723, 5506053, 5506113): Authenticated users could disclose in-memory data through crafted inputs.
- Buffer cache hit ratio always zero (5504681): Monitoring and alerting based on this counter has been producing incorrect data.
- Availability group join failure with 64-character names (5479036): Secondary replicas may be unable to join, affecting HA posture.
- CES dump files on large object streaming (5529461): Production replication workloads using CES could be generating dump files silently.
- Audit sensitivity label gaps (5504495): Compliance audit records may be missing sensitivity information, creating regulatory risk.
Known Issues to Be Aware Of
CU9 documents three known issues that are not yet resolved in this release.
SESSION_CONTEXT in Parallel Plans
Queries using the SESSION_CONTEXT function may return incorrect results or trigger access violation dump files when running in parallel query plans. This occurs because of how SESSION_CONTEXT interacts with parallel execution threads, particularly when a session is reset for reuse (for example, in connection pooling scenarios). If your application uses SESSION_CONTEXT and you have queries that go parallel, this is a meaningful risk. Consider adding OPTION (MAXDOP 1) to queries that use SESSION_CONTEXT as a workaround until a fix is available.
MSDASQL Linked Server Queries Fail with Error 7416
Linked server queries using the MSDASQL (OLE DB Provider for ODBC Drivers) provider with a provider string (@provstr) will fail with: Msg 7416, Level 16 - Access to the remote server is denied because no login-mapping exists. A stricter connection validation check introduced in the engine rejects certain configurations that previously worked. This is a regression. If you have linked servers using MSDASQL with a provider string, test this before deploying CU9 to production. Check the documented workarounds in the linked KB article.
Access Violation Querying sys.dm_exec_requests During Recovery
Querying sys.dm_exec_requests while a database is recovering (during RESTORE, startup recovery, or before an AG replica comes online) can trigger an access violation and generate a dump file. The error log will contain entries referencing EXCEPTION_ACCESS_VIOLATION and SQLDump files. This is particularly relevant if you have monitoring queries that poll sys.dm_exec_requests continuously, as they may coincide with a recovery window and cause a process termination. Consider suppressing or pausing such queries during known recovery windows.
Does This Affect You? How to Check
Build version check - are you already patched?
SELECT
SERVERPROPERTY('ProductVersion') AS Build,
SERVERPROPERTY('ProductLevel') AS Level;
-- CU9 installs build 17.0.5005.3
-- If your build is lower than this, CU9 is not applied
Do you use SESSION_CONTEXT? (known issue)
SELECT OBJECT_NAME(object_id) AS ProcOrFunction, definition
FROM sys.sql_modules
WHERE definition LIKE '%SESSION_CONTEXT%';
If this returns rows, review whether those objects are called from parallel-eligible queries.
Do you have MSDASQL linked servers? (known issue)
SELECT name, provider, provstr
FROM sys.servers
WHERE is_linked = 1
AND provider = 'MSDASQL'
AND provstr IS NOT NULL AND provstr <> '';
If this returns rows, test your linked server queries in a non-production environment before deploying CU9.
Do you have monitoring queries polling sys.dm_exec_requests? (known issue)
Search your monitoring tool configurations and any SQL Agent jobs for references to sys.dm_exec_requests. If they run continuously, plan to suppress them during any recovery windows post-upgrade.
Do you use natively compiled stored procedures? (5482770, 5482825, 5482831)
SELECT OBJECT_NAME(object_id) AS NativeProc
FROM sys.sql_modules
WHERE uses_native_compilation = 1;
Do you use Always Encrypted with enclaves? (5486869, 5486988, 5502845)
SELECT name, encryption_type_desc
FROM sys.column_encryption_keys;
-- Also check:
SELECT * FROM sys.configurations WHERE name = 'column encryption enclave type';
Do you use availability groups with long names? (5479036)
SELECT name, LEN(name) AS NameLength, cluster_type_desc
FROM sys.availability_groups
WHERE LEN(name) = 64;
Do you use Change Event Streaming or replication? (5529457, 5529461)
SELECT name, type_desc
FROM sys.publications;
-- For CES, check your replication topology documentation
Do you use PolyBase or external data sources? (5487460, 5494995)
SELECT name, type_desc, location
FROM sys.external_data_sources;
Do you use BULK INSERT or OPENROWSET with XML format files? (5499864)
Search SQL Agent job steps and application code for references to OPENROWSET(BULK or BULK INSERT combined with FORMATFILE. This is a manual review task.
Is your Buffer cache hit ratio counter showing zero? (5504681)
Open Windows Performance Monitor and check the SQLServer:Buffer Manager - Buffer cache hit ratio counter. If it reads 0 consistently regardless of workload, this fix applies to you.
Do you use managed backup to Azure? (5383382)
SELECT * FROM msdb.dbo.smart_admin_backup_config_defaults;
-- If this returns rows, managed backup is configured
How to Apply
- Download CU9 from the Microsoft Download Centre. No registration is required.
- Test in non-production first. Given the three documented known issues - particularly the MSDASQL regression - validate your linked server configurations and SESSION_CONTEXT usage before touching production.
- Take a full backup of all databases, including system databases, before applying the update.
- Plan for a service restart. CU installation requires a SQL Server service restart. Schedule this during a maintenance window and communicate expected downtime to application teams.
- For availability groups, patch secondary replicas first, fail over, then patch the former primary. This minimises downtime.
- Verify the build after installation:
SELECT SERVERPROPERTY('ProductVersion') AS Build;
-- Expected: 17.0.5005.3
- Review the SQL Server error log after startup for any unexpected entries before returning the instance to production traffic.
DBA Services Recommendation
For DBA Services managed clients, cumulative update assessment and deployment is handled as part of your managed service agreement. We evaluate each CU against your specific environment - checking for relevant known issues, feature usage, and scheduling patching within agreed maintenance windows - so you are not left deciding whether 44 fixes apply to you on your own. If you are not a managed client and would like to discuss proactive patching for your SQL Server estate, get in touch with our team.
Get a SQL Server Health Check for $999
Find out what's really going on inside your SQL Server environment. We find critical misconfigurations in 97% of reviews, with a full 48-hour performance baseline and a prioritised action plan.
$999 ex-GST per instance
normally $2,499