{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/marklogic-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-7557"},{"cvss":9.9,"id":"CVE-2026-8709"},{"cvss":9.1,"id":"CVE-2026-9190"},{"cvss":9.8,"id":"CVE-2026-9192"},{"cvss":9.9,"id":"CVE-2026-9193"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MarkLogic Server"],"_cs_severities":["high"],"_cs_tags":["vulnerability","security-advisory","patch-management"],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eProgress Software Corporation has issued a critical security advisory regarding multiple vulnerabilities identified in MarkLogic Server. The affected versions include all releases prior to 11.3.6 and 12.0.3. This bulletin addresses ten distinct CVEs: CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, and CVE-2026-9203. The advisory provides critical patches to address security risks within the platform. Organizations currently utilizing these versions of MarkLogic Server are urged to review the official bulletin and prioritize patching to mitigate potential exploitation of these vulnerabilities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe identified vulnerabilities present a significant security risk to organizations hosting MarkLogic Server. Failure to apply the necessary security updates may leave systems susceptible to exploitation by unauthorized parties. The specific impact of these vulnerabilities varies depending on the nature of the security flaws described in the bulletin, but critical vulnerabilities often lead to unauthorized remote code execution, denial of service, or escalation of privileges within the enterprise environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of MarkLogic Server within the enterprise environment and verify if they are running versions below 11.3.6 or 12.0.3.\u003c/li\u003e\n\u003cli\u003ePatch all affected MarkLogic Server instances to version 11.3.6, 12.0.3, or later as specified in the Progress Critical Security Alert Bulletin.\u003c/li\u003e\n\u003cli\u003eReview the official Progress MarkLogic Critical Security Alert Bulletin for detailed technical mitigations related to CVE-2026-7326, CVE-2026-7327, CVE-2026-7329, CVE-2026-7557, CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, and CVE-2026-9203.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T21:26:43Z","date_published":"2026-08-06T21:26:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-progress-marklogic-advisory/","summary":"Progress Software has released a security bulletin addressing ten critical vulnerabilities, including CVE-2026-7326 through CVE-2026-9203, affecting MarkLogic Server versions prior to 11.3.6 and 12.0.3.","title":"Critical Security Vulnerabilities in Progress MarkLogic Server","url":"https://feed.craftedsignal.io/briefs/2026-08-progress-marklogic-advisory/"}],"language":"en","title":"CraftedSignal Threat Feed - MarkLogic Server","version":"https://jsonfeed.org/version/1.1"}