Microsoft has published SQL Server 2022 CU22 + GDR (KB5072936) as a security update for build 16.0.4230.2. The release notes say it contains fixes and resolves vulnerabilities, and the packet specifically identifies CVE-2026-20803, a Microsoft SQL Server Elevation of Privilege Vulnerability.

The update includes 1 verified fix. In the release notes, Microsoft also lists the updated SQL Server file version as 2022.160.4230.2.

Improvements and fixes

This release contains a single documented update in SQL Server Engine for Linux and Windows:

  • Security Infrastructure: Restricts privileges for the DBCC stackdump so that only sysadmin can invoke the dump file. Microsoft tags this change with bug reference 4840805.

That is the only verified fix in the packet, so the scope of the release is fairly narrow and centered on security-related engine behavior.

Known issues

The verified packet does not list any known issues for this release.

Version and package details

  • Product version: SQL Server 2022
  • Update name: CU22 + GDR
  • KB: KB5072936
  • Build number: 16.0.4230.2
  • Official release date: 2026-01-13

This is a security-focused SQL Server 2022 update, so administrators tracking update history may want to note both the build change and the single engine-level security infrastructure fix.

Official source