Esecurityplanet Progress Patches High-Severity Flaws in Telerik Fiddler Classic
Article Content
- •Four vulnerabilities in Telerik Fiddler Classic patched, including a high-severity flaw.
- •CVE-2026-77805 allows local privilege escalation via weak executable signature verification.
- •Users must upgrade to version 6.0.20262.10021 or later to mitigate risks.
Progress Software has released patches for four vulnerabilities in Telerik Fiddler Classic, including a high-severity flaw (CVE-2026-77805) that allows local privilege escalation through weak executable signature verification. The vulnerabilities affect versions prior to 6.0.20262.10021 and require local access or user interaction for exploitation. CVE-2026-77804, a medium-severity flaw, involves a TOCTOU race condition that could allow an attacker to install a malicious root certificate. Other vulnerabilities include CVE-2026-77802, an HTTP request smuggling issue, and CVE-2026-77803, which has a low severity rating. Users are advised to upgrade to the latest version to mitigate risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Telerik and CVE-2026-77802 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Fiddler Classic are affected?
What should users do to protect themselves?
Are these vulnerabilities actively exploited?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…