These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-12T16:17:14.050Z and has not been modified since then. CVE-2026-65941 is a high-severity vulnerability affecting WhatsUp Gold versions before 2026.0.2, allowing unauthenticated remote attackers to execute arbitrary code in the context of the IIS application service account. This vulnerability has a [truncated]
WhatsUp Gold versions before 2026.0.2 are vulnerable to an issue allowing a privileged attacker to create a LogToFile action with an arbitrary file extension within the IIS web root. This could potentially lead to arbitrary file creation within the web root, allowing for further exploitation. The vulnerability was published on 2026-08-12 and has not been modified since then. Evidence is limited; further v [truncated]
The CVE-2026-65938 vulnerability affects WhatsUp Gold versions released before 2026.0.2, allowing any authenticated user to invoke restricted actions in the Scheduled Reports API due to an improper authorization vulnerability. This vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Organizations using affected versions should be aware of this vulnerability and take steps to patch [truncated]
A critical cross-site scripting vulnerability exists in Progress MarkLogic Server's Query Console, affecting versions before 11.3.6 and 12.0.3. An attacker can exploit this by crafting a URL that, when visited by an authenticated administrator, executes arbitrary JavaScript in the administrator's browser session. This allows the attacker to capture credentials and perform actions as the administrator.
CVE-2026-9193 is an improper privilege management vulnerability in Progress MarkLogic Server's Hadoop integration. An authenticated user with a low-privileged Hadoop role can escalate privileges and execute privileged operations against the Security database. This vulnerability has a CVSS score of 9.9, indicating critical severity. The CVE record was published on 2026-08-05T16:17:10.183Z and has not been [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T16:17:10.063Z and has not been modified since then. The authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named u [truncated]
An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Serv [truncated]
An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. The CVE record was published on 2026-08-05T16:17:09.437Z and h [truncated]
The CVE-2026-7327 record describes an improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before versions 11.3.6 and 12.0.3. An authenticated user with an administrative REST role can exploit this vulnerability to escalate privileges, potentially allowing unauthorized access to sensitive server-side data. Administrators and users of Progres [truncated]