Skip to content
Progress Patches High-Severity Flaws in Telerik Fiddler Classic

Progress Patches High-Severity Flaws in Telerik Fiddler Classic

First seen 7 Oct 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 18:57 UTC
  • •Four vulnerabilities in Telerik Fiddler Classic patched, including a high-severity flaw.
  • •CVE-2026-77805 allows local privilege escalation via weak executable signature verification.
  • •Users must upgrade to version 6.0.20262.10021 or later to mitigate risks.

Progress Software has released patches for four vulnerabilities in Telerik Fiddler Classic, including a high-severity flaw (CVE-2026-77805) that allows local privilege escalation through weak executable signature verification. The vulnerabilities affect versions prior to 6.0.20262.10021 and require local access or user interaction for exploitation. CVE-2026-77804, a medium-severity flaw, involves a TOCTOU race condition that could allow an attacker to install a malicious root certificate. Other vulnerabilities include CVE-2026-77802, an HTTP request smuggling issue, and CVE-2026-77803, which has a low severity rating. Users are advised to upgrade to the latest version to mitigate risks associated with these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-05
Patches released for Fiddler Classic vulnerabilities
Progress Software released version 6.0.20262.10021 to address four vulnerabilities, including critical issues affecting local privilege escalation.
Esecurityplanet
2026-10-05
CVE-2026-77805 published
High-severity flaw allows local privilege escalation through weak executable signature verification, CVSS score of 7.9.
Esecurityplanet
2026-10-05
CVE-2026-77804 published
Medium-severity TOCTOU race condition vulnerability allows installation of malicious root certificates.
Esecurityplanet
2026-10-05
CVE-2026-77803 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
CVE-2026-77802 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track Telerik and CVE-2026-77802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Fiddler Classic are affected?
All versions prior to 6.0.20262.10021 are affected by the vulnerabilities.
What should users do to protect themselves?
Users should upgrade to the latest version, 6.0.20262.10021, to mitigate the risks associated with these vulnerabilities.
Are these vulnerabilities actively exploited?
No confirmed active exploitation has been reported; however, local access is required for potential exploitation.