Skip to content
Threat Feed
high advisory

Security Updates for Progress Telerik Fiddler Classic and Sitefinity Next.js SDK

Progress Software has issued patches for vulnerabilities in Telerik Fiddler Classic, including CVE-2026-77805, and the Sitefinity Next.js SDK.

CVE search metadata

CVE search record: CVE-2026-77805. Severity: high. CVSS: 7.9. KEV: no. Product: Telerik Fiddler Classic (< 6.0.20262.10021), @progress/sitefinity-nextjs-sdk (< 15.4.8638). Brief: Security Updates for Progress Telerik Fiddler Classic and Sitefinity Next.js SDK. Brief link: https://feed.craftedsignal.io/briefs/2026-10-progress-advisories/

Progress Software has released security updates to address vulnerabilities affecting Telerik Fiddler Classic and the Sitefinity Next.js SDK. Telerik Fiddler Classic is affected by a weak executable signature verification vulnerability, tracked as CVE-2026-77805. This vulnerability may allow for unauthorized manipulation of executable signatures, potentially facilitating the execution of malicious code. Additionally, security vulnerabilities have been identified within the Sitefinity Next.js SDK. Users and administrators are advised to upgrade Telerik Fiddler Classic to version 6.0.20262.10021 or later, and the Sitefinity Next.js SDK to version 15.4.8638 or later. These updates are critical to prevent potential exploitation of the identified security weaknesses in these products.

Impact

Successful exploitation of these vulnerabilities could result in unauthorized code execution or the bypassing of security controls within affected environments. The specific impact depends on the environment in which these tools are deployed, particularly for administrative or development workstations running Fiddler or web applications utilizing the vulnerable SDK.

Recommendation

Prioritized actions for security and IT operations teams:

  • Upgrade all instances of Telerik Fiddler Classic to version 6.0.20262.10021 or later immediately to mitigate CVE-2026-77805.
  • Upgrade the @progress/sitefinity-nextjs-sdk dependency to version 15.4.8638 or later in all active projects.
  • Review the Progress Trust Center for further details on mitigation and configuration changes required to secure affected deployments.

Mitigations

Upgrade Telerik Fiddler Classic to 6.0.20262.10021

immediate IT Operations

CVE-2026-77805

Upgrade @progress/sitefinity-nextjs-sdk to 15.4.8638

immediate IT Operations

Sitefinity Next.js SDK vulnerabilities