Progress security advisory (AV26-781)
Serial number: AV26-781 Date: August 5, 2026 As of August 5, 2026, Progress Software Corporation is affected by vulnerabilities in the following product: MarkLogic Server Prior to 11.3.6 Prior to 12.0.3 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Marklogic Critical Security Alert Bulletin – August 2026 – (CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, CVE-2026-9203) Progress Trust Center
CSIRTS triage
- What
- Multiple critical vulnerabilities in MarkLogic Server.
- Who is affected
- MarkLogic Server deployments running versions below 11.3.6 and 12.0.3 worldwide.
- Urgency
- Critical urgency; severity marked as critical with 10 CVEs assigned indicating active exploitation risk or high impact.
- Action
- Immediately upgrade MarkLogic Server to version 11.3.6 or 12.0.3 depending on the currently deployed branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch MarkLogic Server
Get an email when a new MarkLogic Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-781
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-73260.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-73270.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-73290.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-75570.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-87090.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-91900.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-91920.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-91930.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-91950.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-92030.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-7326 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7327 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7329 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7557 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-8709 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9190 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9192 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9193 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9195 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9203 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-9203: A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0…nvd
- criticalCVE-2026-9195: A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 1…nvd
- criticalCVE-2026-9193: An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic …nvd
- criticalCVE-2026-9192: An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server befo…nvd
- criticalCVE-2026-9190: An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server bef…nvd
- criticalCVE-2026-8709: An improper privilege management vulnerability in the REST API document patch operation of Prog…nvd
- criticalCVE-2026-7557: An improper verification of cryptographic signature vulnerability in the SAML authentication mo…nvd
- criticalCVE-2026-7329: An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfa…nvd
- highCVE-2026-7327: An improper privilege management vulnerability in the REST API document processing pipeline of …nvd
- highCVE-2026-7326: A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before …nvd
More from Canadian Centre for Cyber Security
- unknownDjango security advisory (AV26-786)2026-08-06
- unknownCisco security advisory (AV26-785)2026-08-06
- unknownFoxit security advisory (AV26-784)2026-08-06
- unknownGitHub security advisory (AV26-783)2026-08-06
- unknownJenkins security advisory (AV26-782)2026-08-06