Canada urges updates for Progress Fiddler, Sitefinity, and ARCGenAI
Canada's Cyber Centre issued two October 2026 advisories urging updates for Progress Fiddler Classic, Sitefinity Next.js SDK, and ARCGenAI-Generator, with no exploitation reported.
The Canadian Centre for Cyber Security published advisory AV26-999 on 5 October 2026, urging updates for Telerik Fiddler Classic before 6.0.20262.10021 and @progress/sitefinity-nextjs-sdk before 15.4.8638. That notice cites CVE-2026-77805, a weak executable signature verification vulnerability, and links a Sitefinity critical advisory about Next.js vulnerabilities. On 6 October 2026, advisory AV26-1005 warned of CVE-2026-91140 in Progress Software's ARCGenAI-Generator, part of Autonomous REST Connector GenAI Agents, in versions before 2.1, pointing to Progress's September 2026 DataDirect critical security alert. Neither bulletin reports active exploitation, and both tell users to review vendor guidance and apply updates. The advisories cover different products and CVEs rather than conflicting accounts of a single flaw.
- Canadian Centre for Cyber Security advisory AV26-999, dated 5 October 2026, covers Telerik Fiddler Classic before 6.0.20262.10021.
- AV26-999 also lists @progress/sitefinity-nextjs-sdk before 15.4.8638 and links a Sitefinity critical advisory about Next.js vulnerabilities.
- CVE-2026-77805 is described as a weak executable signature verification vulnerability.
- Advisory AV26-1005, dated 6 October 2026, covers Progress ARCGenAI-Generator before version 2.1 in the Autonomous REST Connector GenAI Agents component.
- CVE-2026-91140 is tied to Progress's September 2026 DataDirect critical security alert.
- Neither bulletin reports active exploitation; both urge administrators to review vendor guidance and apply updates.
Coverage timelineoldest first · each row is one article
- · 3d agoProgress security advisory (AV26-999)
Canadian Centre for Cyber Security· 42
Canada's Cyber Centre urges updates for Progress Fiddler Classic and the Sitefinity Next.js SDK.
- · 2d agoProgress security advisory (AV26-1005)
Canadian Centre for Cyber Security· 28
Canada's Cyber Centre warns of CVE-2026-91140 in Progress ARCGenAI-Generator before version 2.1.
Vulnerabilities in this storyAll →
- CVE-2026-778057.9—Weak helper signature check in Fiddler Classic enables local privescpublished · Progress Software Telerik Fiddler Classic for Windows
- CVE-2026-911409.6—OS Command Injection via Malicious OpenAPI Docs in Progress ARCGenAI-Generator 2.0published · Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator
| CVE | Vulnerability |
|---|