CVE-2026-7326
Serial number: AV26-781 Date: August 5, 2026 As of August 5, 2026, Progress Software Corporation is affected by vulnerabilities in the following product: MarkLogic Server Prior to 11.3.6 Prior to 12.0.3 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Marklogic Critical Security Alert Bulletin – August 2026 – (CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, CVE-2026-9203) Progress Trust Center
CSIRTS triage
- What
- Multiple critical vulnerabilities in MarkLogic Server.
- Who is affected
- MarkLogic Server deployments running versions below 11.3.6 and 12.0.3 worldwide.
- Urgency
- Critical urgency; severity marked as critical with 10 CVEs assigned indicating active exploitation risk or high impact.
- Action
- Immediately upgrade MarkLogic Server to version 11.3.6 or 12.0.3 depending on the currently deployed branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-7326
Get an email if CVE-2026-7326 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
Advisory coverage (2)
- criticalProgress security advisory (AV26-781)cccs · 2026-08-06
- highCVE-2026-7326: A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before …nvd · 2026-08-05
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-7326)