Full Report
Progress security advisory (AV26-999)
Analysis Summary
# Vulnerability: Progress Software Security Updates (October 2026)
## CVE Details
- **CVE ID:** CVE-2026-77805 (Telerik Fiddler) / Unspecified CVEs related to Next.js (Sitefinity)
- **CVSS Score:** Critical (Numerical score not specified in source, but categorized as "Critical Security Advisory")
- **CWE:** CWE-347 (Improper Verification of Cryptographic Signature - specific to Fiddler)
## Affected Systems
- **Products:**
1. Progress Telerik Fiddler Classic
2. @progress/sitefinity-nextjs-sdk
- **Versions:**
1. Telerik Fiddler Classic: Versions prior to 6.0.20262.10021
2. sitefinity-nextjs-sdk: Versions prior to 15.4.8638
- **Configurations:** Systems utilizing Sitefinity integrated with the Next.js SDK and environments where Fiddler Classic is used for web debugging.
## Vulnerability Description
This advisory covers two distinct issues:
1. **Weak Executable Signature Verification:** In Telerik Fiddler Classic, the application fails to properly validate the cryptographic signatures of executables. This flaw could allow an attacker to bypass security checks and potentially execute untrusted or malicious code.
2. **Next.js SDK Vulnerabilities:** The Sitefinity Next.js SDK was found to be susceptible to underlying security vulnerabilities inherited from the Next.js framework, necessitating a critical update to the SDK to ensure secure communication and rendering between Sitefinity and the frontend.
## Exploitation
- **Status:** Not explicitly stated as exploited in the wild; however, categorized as a "Critical Advisory."
- **Complexity:** Medium (Signature verification bypasses often require local or man-in-the-middle positioning).
- **Attack Vector:** Network / Local.
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
- *Note: Improper signature verification typically leads to full system compromise via arbitrary code execution.*
## Remediation
### Patches
Progress Software has released the following updated versions to address these flaws:
- **Telerik Fiddler Classic:** Update to version **6.0.20262.10021** or later.
- **Sitefinity Next.js SDK:** Update to version **15.4.8638** or later.
### Workarounds
- No specific workarounds provided. Users are strongly encouraged to apply the official patches immediately to mitigate risks.
## Detection
- **Indicators of compromise:** Monitor for unauthorized executable launches initiated by the Fiddler process.
- **Detection methods:** Audit installed software versions for Telerik Fiddler and Sitefinity SDK dependencies (package.json for Next.js projects) to ensure they meet the minimum secure version requirements.
## References
- Progress Telerik Fiddler Knowledge Base: hxxps[://]www[.]telerik[.]com/fiddler/fiddler-classic/documentation/knowledge-base/kb-security-weak-executable-signature-verification-cve-2026-77805
- Sitefinity Community Advisory: hxxps[://]community[.]progress[.]com/s/article/Sitefinity-Critical-Security-Advisory-for-Addressing-Security-Vulnerabilities-in-Next-js-September-2026
- Progress Trust Center: hxxps[://]trust[.]progress[.]com/
- Canadian Centre for Cyber Security (AV26-999): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/progress-security-advisory-av26-999