{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aowaspowasp_modsecurity_core_rule_set/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:progress:sitefinity:*:*:*:*:*:*:*:*","cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*","cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*","cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*","cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-7312"},{"cvss":9.8,"id":"CVE-2026-7198"},{"cvss":8.7,"id":"CVE-2026-7313"},{"cvss":9.6,"id":"CVE-2026-8037"},{"cvss":6.8,"id":"CVE-2026-33691"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CBFB47A0-CA83-566E-88FB-C2AD0B92470A\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Sitefinity CMS (multiple versions)","Sitefinity Insight (multiple versions)","Progress Kemp LoadMaster (GA v7.2.63.1 and prior)","Progress Kemp LoadMaster (LTSF v7.2.54.17 and prior)","Kemp LoadMaster","LoadMaster"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","web-application","cms","load-balancer","patch-management","cve"],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eBetween June 2 and 4, 2026, Progress Software released urgent security advisories (AV26-552) addressing a range of vulnerabilities across its product line, notably including critical updates for Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster. These advisories detail several CVEs, specifically CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313 affecting Sitefinity products, and CVE-2026-8037, CVE-2026-33691 impacting Kemp LoadMaster appliances. The vulnerabilities could allow for unauthorized access, remote code execution, or denial-of-service, posing a significant risk to organizations utilizing these products. Defenders must prioritize the immediate application of patches to prevent potential exploitation by malicious actors seeking to compromise critical web applications and network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eVulnerable System Identification:\u003c/strong\u003e An attacker identifies an unpatched Progress Sitefinity CMS, Sitefinity Insight, or Kemp LoadMaster instance exposed to the internet, potentially via automated scanning tools.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Vulnerability Exploitation:\u003c/strong\u003e The attacker crafts and sends a malicious request or payload targeting one of the identified critical vulnerabilities (e.g., CVE-2026-7312 for Sitefinity, CVE-2026-8037 for LoadMaster).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRemote Code Execution (Hypothetical):\u003c/strong\u003e Successful exploitation could lead to remote code execution (RCE), allowing the attacker to execute arbitrary commands on the underlying server, such as spawning a \u003ccode\u003epowershell.exe\u003c/code\u003e or \u003ccode\u003ebash\u003c/code\u003e process.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEstablishing Persistence:\u003c/strong\u003e The attacker deploys a web shell (for CMS) or modifies appliance configuration (for LoadMaster) to maintain unauthorized access, creating a backdoor for future access.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eInternal Reconnaissance \u0026amp; Privilege Escalation:\u003c/strong\u003e The attacker then performs internal reconnaissance, enumerating system configurations, user accounts, and network topology, seeking to escalate privileges within the compromised environment.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLateral Movement \u0026amp; Data Access:\u003c/strong\u003e Using gained privileges, the attacker moves laterally across the network to access sensitive data, intellectual property, or other critical systems.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact Execution:\u003c/strong\u003e Depending on the attacker's objectives, this could culminate in data exfiltration, deployment of ransomware, or disruption of critical load balancing services.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of these vulnerabilities could lead to severe consequences for affected organizations. For Sitefinity CMS and Insight, compromise could result in unauthorized access to sensitive data, defacement of public-facing web properties, full control over the content management system, or the ability to launch further attacks against visitors. For Kemp LoadMaster, exploitation could allow attackers to bypass security controls, redirect network traffic, disrupt essential load-balancing services, or gain a foothold within the network infrastructure. Ultimately, these vulnerabilities pose a risk of significant data breaches, operational downtime, and reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691 on all affected Progress Sitefinity CMS, Sitefinity Insight, and Kemp LoadMaster instances immediately.\u003c/li\u003e\n\u003cli\u003eEnable detailed web server logging for Sitefinity instances (logsource: webserver) to capture unusual HTTP requests targeting known vulnerable paths, and deploy the \u0026quot;Detect Possible Sitefinity CMS Web Exploitation Attempts\u0026quot; Sigma rule.\u003c/li\u003e\n\u003cli\u003eImplement process creation monitoring on Windows systems hosting Sitefinity (logsource: process_creation) and deploy the \u0026quot;Detect Web Server Spawning Suspicious Child Process\u0026quot; Sigma rule to identify post-exploitation activity.\u003c/li\u003e\n\u003cli\u003eEnable network connection logging on web servers (logsource: network_connection) and deploy the \u0026quot;Detect Suspicious Outbound Network Connection from Web Server Process\u0026quot; Sigma rule to detect potential command and control (C2) communications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T18:47:31Z","date_published":"2026-06-14T14:21:34Z","id":"https://feed.craftedsignal.io/briefs/2026-06-progress-security-advisory/","summary":"Progress released critical security advisories between June 2 and 4, 2026, addressing multiple vulnerabilities, including CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691, in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster, which could lead to various impacts if exploited, necessitating immediate patching.","title":"Progress Security Advisory (AV26-552) Addressing Multiple Critical Vulnerabilities","url":"https://feed.craftedsignal.io/briefs/2026-06-progress-security-advisory/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}