CVE-2026-7557: An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-7557
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-75570.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7557 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalProgress security advisory (AV26-781)cccs
Recent advisories for An improper verification
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…nvd · 2026-08-01
- mediumCVE-2026-13305: Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signatu…nvd · 2026-07-29
- highCVE-2026-14837: Multiple Lenze products are affected by an improper signature verification vulnerability in th…nvd · 2026-07-27
- highCVE-2026-64623: Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerabili…nvd · 2026-07-20
- unknownCVE-2026-15925: Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 a…nvd · 2026-07-16
- highCVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to by…nvd · 2026-07-14
More from NVD Recent CVEs
- highCVE-2026-8325: A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds …2026-08-06
- highCVE-2026-7867: A flaw was found in udisks2. A local attacker with an active console session can exploit insuff…2026-08-06
- highCVE-2026-7406: A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untr…2026-08-06
- mediumCVE-2026-7405: A maliciously crafted TIF file, when parsed through certain Autodesk products during image impo…2026-08-06
- mediumCVE-2026-71555: PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.…2026-08-06