Multiple Critical Vulnerabilities in Progress Sitefinity Disclosed
ID: 8a770026-7bf5-5c4e-b1ef-a9397abda762
STIX ID: report--8a770026-7bf5-5c4e-b1ef-a9397abda762
Feed Name: ThreatCluster
Three critical vulnerabilities in Progress Sitefinity (CVE-2026-7195, CVE-2026-7312, CVE-2026-7201) were disclosed on 2026-06-02 affecting multiple 14.x and 15.x versions; issues include improper input validation, insufficiently protected credentials (exposing plaintext credentials), and an authorization bypass allowing modification of user properties. Vendors have published patches for the affected versions and organizations are urged to apply updates, restrict access to Sitefinity web services, and review non-default configurations and integrations (e.g., Sitefinity Insight). No public proof-of-concept exploits or IOCs are reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
