Sign in with Microsoft
Sign in or create an account.
Select a different account.
You have multiple accounts
Choose the account you want to sign in with.


A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services if it incorrectly handles page requests. An attacker who successfully exploits this vulnerability could execute code in the context of the Report Server service account. An internal API that is used for large PBIX file requests allows a file path property. The reporting services process may try to write a temporary file to a remote path. If the NTLM hash is broken on a target computer, the attacker could get the credentials for the report server process. To learn more about the vulnerability, seeĀ CVE-2021-26859.

Power BI Report Server is updated to the following builds in this security update.

Product name

Product version

File version

Power BI Report Server



How to obtain and install the update

This update is available for download from the Microsoft Download Center:

Release Date: March 9, 2021


To apply this update, you must have any version of Power BI Report Server (October 2020) installed.

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Was this information helpful?

What affected your experience?
By pressing submit, your feedback will be used to improve Microsoft products and services. Your IT admin will be able to collect this data. Privacy Statement.

Thank you for your feedback!