Progress security advisory (AV26-999)
Canada's Cyber Centre urges updates for Progress Fiddler Classic and the Sitefinity Next.js SDK.
Canadian Centre for Cyber Security advisory AV26-999, dated 5 October 2026, says Progress Software products need updates. Telerik Fiddler Classic before 6.0.20262.10021 and @progress/sitefinity-nextjs-sdk before 15.4.8638 are listed. The notice cites CVE-2026-77805, a weak executable signature verification vulnerability, and links a Sitefinity critical advisory about Next.js vulnerabilities. Exploitation is not reported.
- AV26-999 covers Fiddler Classic before 6.0.20262.10021.
- Sitefinity Next.js SDK before 15.4.8638 is also affected.
- CVE-2026-77805 is a weak executable signature verification flaw.
- Users are told to review vendor links and apply updates.
Vulnerabilities mentionedAll →
- CVE-2026-778057.9—Weak helper signature check in Fiddler Classic enables local privescpublished · Progress Software Telerik Fiddler Classic for Windows
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-77805 | Weak helper signature check in Fiddler Classic enables local privesc Progress Telerik Fiddler Classic for Windows before version 6.0.20262.10021 does not adequately verify the integrity of external helper tools it launches. Before running a helper, it only checks that the file has a valid Authenticode signature whose certificate subject matches a broad allow list of publisher name fragments, instead of confirming it is the specific executable shipped with that product version. A local attacker with low privileges can replace a helper with any other validly signed binary from an allow-listed publisher so that, when a user starts the tool and approves the elevation prompt without noticing it names a different executable, the substitute runs—including as Administrator for tools that request elevation—yielding privilege escalation and unintended code execution. Windows users of affected Fiddler Classic builds are impacted. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article76 words · extracted from cyber.gc.ca · click to collapse
Serial Number: AV26-999
Date: October 5, 2026
As of October 5, 2026, Progress Software is affected by vulnerabilities in the following product:
- Progress Telerik Fiddler Classic
- Prior to 6.0.20262.10021
- @progress/sitefinity-nextjs-sdk
- Prior to 15.4.8638
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/progress-security-advisory-av26-999