Progress Marklogic Server — known CVE vulnerabilities
Every CVE whose affected-product data names Progress Marklogic Server, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (10)
CVE-2026-7329 — CVSS 9.9 (critical): An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before…
CVE-2026-9193 — CVSS 9.9 (critical): An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an…
CVE-2026-8709 — CVSS 9.9 (critical): An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and…
CVE-2026-9192 — CVSS 9.8 (critical): An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an…
CVE-2026-9195 — CVSS 9.3 (critical): A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker…
CVE-2026-7557 — CVSS 9.1 (critical): An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before…
CVE-2026-9190 — CVSS 9.1 (critical): An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote…
CVE-2026-9203 — CVSS 8.5 (high): A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with…
CVE-2026-7327 — CVSS 8.1 (high): An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and…
CVE-2026-7326 — CVSS 7.5 (high): A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker…