Progress Software issued a critical security bulletin for MarkLogic Server covering 10 vulnerabilities, with 7 rated critical and 3 rated high severity, and urged customers to upgrade immediately. The flaws affect releases before 11.3.6 in the 11.x branch and before 12.0.3 in the 12.x branch and span the HTTP App Server, ODBC App Server, Query Console, REST API document patch operation, Hadoop integration, and AWS deployments. Government advisories from Canada and Italy echoed the vendor warning and directed administrators to apply the available updates.
The most serious issues include CVE-2026-9192, an authentication bypass in the ODBC App Server that can let an unauthenticated attacker run queries as any known user, including administrators; CVE-2026-9190, an HTTP request smuggling flaw that can bypass authentication and hijack sessions; CVE-2026-9193 and CVE-2026-8709, privilege-escalation bugs that can grant low-privileged users access to the Security database; CVE-2026-9195, a Query Console XSS issue that can execute attacker-controlled JavaScript in an administrator session; and CVE-2026-9203, an SSRF vulnerability on AWS that can expose cloud instance metadata and credentials. Progress said successful exploitation could give attackers unauthorized access to, or control over, affected MarkLogic Server instances.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-781 warning that multiple vulnerabilities affect Progress MarkLogic Server prior to versions 11.3.6 and 12.0.3. The notice directed users and administrators to review vendor advisories and apply updates as they become available.
In the August 2026 bulletin, Progress said patched versions of MarkLogic Server were available and strongly recommended customers upgrade immediately. The fixes address 10 vulnerabilities affecting the product.
Progress issued a critical security alert bulletin for MarkLogic Server covering 10 CVEs, including CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, and CVE-2026-9203. The company said exploitation could allow unauthorized access to or control of affected instances.
Several MarkLogic Server vulnerabilities, including CVE-2026-8709, CVE-2026-9190, CVE-2026-9192, CVE-2026-9193, CVE-2026-9195, and CVE-2026-9203, were received by security@progress.com. The issues span privilege escalation, request smuggling, authentication bypass, XSS, and SSRF flaws.
Italy's ACN reported that Progress released security updates for MarkLogic Server to fix 10 vulnerabilities, seven rated critical and three rated high. The notice advised users to update affected installations in line with the vendor bulletin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecert.gov.py
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecommunity.progress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.