sql_server_2016 vulnerabilities
CVEs whose affected-version data names the sql_server_2016 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-47296High· 7.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
▾ Twilightmicrosoft · sql_server_2016EPSS 0.50%via NVD
CVE-2026-21262High· 8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
▾ Twilightmicrosoft · sql_server_2016EPSS 2.0%via NVD