A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 88.00 |
| Exploitation signal(KEV listed) | ×1.50 |
| VPI | 100.00 |
VPI formula vpi-v1
Required Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
This CVE is referenced in a KISA security bulletin (Korean only).
| Source | CVSS Version | Base Score | Severity | Vector String | Assessment Date |
|---|---|---|---|---|---|
| NVDNIST | 3.1 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 04/20/2026 |
| NVDNIST | 2.0 | 6.5 |
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
| AV:N/AC:L/Au:S/C:P/I:P/A:P |
| 04/20/2026 |