CVE-2026-7557
Serial number: AV26-781 Date: August 5, 2026 As of August 5, 2026, Progress Software Corporation is affected by vulnerabilities in the following product: MarkLogic Server Prior to 11.3.6 Prior to 12.0.3 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Marklogic Critical Security Alert Bulletin – August 2026 – (CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, CVE-2026-9203) Progress Trust Center
CSIRTS triage
- What
- Multiple critical vulnerabilities in MarkLogic Server.
- Who is affected
- MarkLogic Server deployments running versions below 11.3.6 and 12.0.3 worldwide.
- Urgency
- Critical urgency; severity marked as critical with 10 CVEs assigned indicating active exploitation risk or high impact.
- Action
- Immediately upgrade MarkLogic Server to version 11.3.6 or 12.0.3 depending on the currently deployed branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-7557
Get an email if CVE-2026-7557 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
Advisory coverage (2)
- criticalProgress security advisory (AV26-781)cccs · 2026-08-06
- criticalCVE-2026-7557: An improper verification of cryptographic signature vulnerability in the SAML authentication mo…nvd · 2026-08-05
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-7557)