{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aprogresstelerik_fiddler_classic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:progress:telerik_fiddler_classic:*:*:*:*:*:*:*:*","cpe:2.3:a:progress:sitefinity_nextjs_sdk:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.9,"id":"CVE-2026-77805"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Telerik Fiddler Classic (\u003c 6.0.20262.10021)","@progress/sitefinity-nextjs-sdk (\u003c 15.4.8638)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eProgress Software has released security updates to address vulnerabilities affecting Telerik Fiddler Classic and the Sitefinity Next.js SDK. Telerik Fiddler Classic is affected by a weak executable signature verification vulnerability, tracked as CVE-2026-77805. This vulnerability may allow for unauthorized manipulation of executable signatures, potentially facilitating the execution of malicious code. Additionally, security vulnerabilities have been identified within the Sitefinity Next.js SDK. Users and administrators are advised to upgrade Telerik Fiddler Classic to version 6.0.20262.10021 or later, and the Sitefinity Next.js SDK to version 15.4.8638 or later. These updates are critical to prevent potential exploitation of the identified security weaknesses in these products.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in unauthorized code execution or the bypassing of security controls within affected environments. The specific impact depends on the environment in which these tools are deployed, particularly for administrative or development workstations running Fiddler or web applications utilizing the vulnerable SDK.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Telerik Fiddler Classic to version 6.0.20262.10021 or later immediately to mitigate CVE-2026-77805.\u003c/li\u003e\n\u003cli\u003eUpgrade the @progress/sitefinity-nextjs-sdk dependency to version 15.4.8638 or later in all active projects.\u003c/li\u003e\n\u003cli\u003eReview the Progress Trust Center for further details on mitigation and configuration changes required to secure affected deployments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:49:01Z","date_published":"2026-10-06T00:49:01Z","id":"https://feed.craftedsignal.io/briefs/2026-10-progress-advisories/","summary":"Progress Software has issued patches for vulnerabilities in Telerik Fiddler Classic, including CVE-2026-77805, and the Sitefinity Next.js SDK.","title":"Security Updates for Progress Telerik Fiddler Classic and Sitefinity Next.js SDK","url":"https://feed.craftedsignal.io/briefs/2026-10-progress-advisories/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:progress:telerik_fiddler_classic:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}