PULSE
LIVE65signals / 24h
FEED
ransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitalityransomincransom reclama a vprj.org · US · Not Foundransompanzer reclama a Surakarta University · ID · Educationransompanzer reclama a Festina Group · CH · Retail & E-Commerceransomclop reclama a nuv******* · Not Foundransomclop reclama a ipm******* · Not Foundransomclop reclama a ecc******* · Not Foundransomclop reclama a st******* · Not Foundransomclop reclama a qc******* · Not Foundransomclop reclama a flu******* · Not Foundransomclop reclama a mid******* · Not Foundransombarracuda reclama a Micro-Comm Inc. · US · Technologyransombarracuda reclama a Namyang Industrial Co., Ltd. \ NAMYANG NEXMO · KR · Manufacturingransombarracuda reclama a RS Automation Co., Ltd. · CN · Manufacturingransomthreeam reclama a clubonecasino.com · US · Hospitalityransomincransom reclama a vprj.org · US · Not Foundransompanzer reclama a Surakarta University · ID · Educationransompanzer reclama a Festina Group · CH · Retail & E-Commerceransomclop reclama a nuv******* · Not Foundransomclop reclama a ipm******* · Not Foundransomclop reclama a ecc******* · Not Foundransomclop reclama a st******* · Not Foundransomclop reclama a qc******* · Not Foundransomclop reclama a flu******* · Not Foundransomclop reclama a mid******* · Not Found
← All CVEs
CVE WatchAug 5, 2026

CVE-2026-9192

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticate

CVSS

9.8

Critical

EPSS

KEV

Exploit Today

0-100

Published: Aug 5, 2026 · Last modified: Aug 5, 2026 · CWE-287

EPSS · 30d

Not enough EPSS history yet.

Technical description

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-189907.3 HIG
A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.6h
CVE-2026-712779.1 CRI
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. `Authorization: fake`) satisfies the guard, granting access to every endpoint protected only by this request guard.17h
CVE-2026-160557.5 HIG
0The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.18h
CVE-2026-160367.5 HIG
0The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the target account's existing factor, allowing an attacker who knows a user's password to rebind that user's second factor to an attacker-controlled destination, complete the challenge, and take over the account, including administrator accounts.17h
CVE-2026-153727.5 HIG
0The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, allowing an attacker who already knows a user's password to bypass two-factor authentication and fully access the account, including administrator accounts.17h
CVE-2026-152109.1 CRI
0The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time login code after a wrong guess, and an unauthenticated user can request a login code for any account. Because the code is a short numeric OTP, an attacker can brute-force it and take over any account, including an administrator's.17h