<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Progress/Sitefinity-Nextjs-Sdk (&lt; 15.4.8638) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@progress/sitefinity-nextjs-sdk--15.4.8638/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:49:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@progress/sitefinity-nextjs-sdk--15.4.8638/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Security Updates for Progress Telerik Fiddler Classic and Sitefinity Next.js SDK</title><link>https://feed.craftedsignal.io/briefs/2026-10-progress-advisories/</link><pubDate>Tue, 06 Oct 2026 00:49:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-progress-advisories/</guid><description>Progress Software has issued patches for vulnerabilities in Telerik Fiddler Classic, including CVE-2026-77805, and the Sitefinity Next.js SDK.</description><content:encoded><![CDATA[<p>Progress Software has released security updates to address vulnerabilities affecting Telerik Fiddler Classic and the Sitefinity Next.js SDK. Telerik Fiddler Classic is affected by a weak executable signature verification vulnerability, tracked as CVE-2026-77805. This vulnerability may allow for unauthorized manipulation of executable signatures, potentially facilitating the execution of malicious code. Additionally, security vulnerabilities have been identified within the Sitefinity Next.js SDK. Users and administrators are advised to upgrade Telerik Fiddler Classic to version 6.0.20262.10021 or later, and the Sitefinity Next.js SDK to version 15.4.8638 or later. These updates are critical to prevent potential exploitation of the identified security weaknesses in these products.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities could result in unauthorized code execution or the bypassing of security controls within affected environments. The specific impact depends on the environment in which these tools are deployed, particularly for administrative or development workstations running Fiddler or web applications utilizing the vulnerable SDK.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT operations teams:</p>
<ul>
<li>Upgrade all instances of Telerik Fiddler Classic to version 6.0.20262.10021 or later immediately to mitigate CVE-2026-77805.</li>
<li>Upgrade the @progress/sitefinity-nextjs-sdk dependency to version 15.4.8638 or later in all active projects.</li>
<li>Review the Progress Trust Center for further details on mitigation and configuration changes required to secure affected deployments.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>