CVE-2026-6009: Jaspersoft JasperReports Io At-Scale
High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
Affected products
- Jaspersoft JasperReports Io At-Scale: up to and including 10.0.0
- Jaspersoft JasperReports Io Professional: up to and including 10.0.0
- Jaspersoft JasperReports Library Community Edition: up to and including 7.0.6
- Jaspersoft JasperReports Library Professional: up to and including 10.0.0
- Jaspersoft JasperReports Server: up to and including 10.0.0
- Jaspersoft JasperReports Web Studio: up to and including 10.0.1
- Jaspersoft Jaspersoft Studio Community Edition: up to and including 7.0.6
- Jaspersoft Jaspersoft Studio Professional: up to and including 10.0.0
Published 2026-05-19. Last modified 2026-07-24.