Skip to main content
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryidentity-authentication-vulnerability

Critical Progress Sitefinity flaws expose credentials and restricted content

Updated 16h agoFirst seen Jun 2, 20267 sources

Progress released security updates for Sitefinity CMS, Sitefinity Insight, and Kemp LoadMaster, with the most urgent attention on multiple severe Sitefinity web-service vulnerabilities affecting versions from 8.0 through 15.4. The Canadian Centre for Cyber Security flagged the vendor advisories and urged administrators to review Progress bulletins and apply patches. Among the Sitefinity issues, CVE-2026-7312 carries a CVSS 10.0 rating and can let an unauthenticated attacker obtain plaintext credentials used for Sitefinity Insight connections when that integration is enabled in a non-default configuration, while CVE-2026-7198 is rated CVSS 9.8 and allows unauthenticated access to restricted content in affected 15.4 deployments.

Additional Sitefinity flaws include CVE-2026-7201, an authorization bypass that can let an authenticated low-privilege user modify other users' account properties, and CVE-2026-7313, which exposes Insight credentials to authenticated back-end users under specific configurations. Progress published patched releases including 15.4.8630, 15.3.8531, 15.2.8441, 15.1.8335, 15.0.8234, 14.4.8152, and 13.3.7652, and warned that delaying remediation leaves OData and related web services open to unauthorized exploitation. The broader advisory set also includes two vulnerabilities affecting Progress Kemp LoadMaster.

Share:
Critical Progress Sitefinity flaws expose credentials and restricted content
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jun 9, 20262d ago

ZDI discloses critical LoadMaster RCE CVE-2026-8037

On 2026-06-09, ZDI disclosed CVE-2026-8037, a critical unauthenticated remote code execution flaw in Progress Kemp LoadMaster's accessv2 endpoint involving the apiuser parameter. The advisory said Progress released an update to remediate the issue, and credited Syed Ibrahim Ahmed of TrendAI Research for the finding.

ZDI-26-342 | Zero Day Initiative
Jun 5, 20265d ago

Progress publishes security updates for Sitefinity and LoadMaster

Between June 2 and June 4, 2026, Progress published security updates addressing critical vulnerabilities in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster. The updates covered multiple Sitefinity CVEs and two LoadMaster CVEs, with patched Sitefinity releases issued for supported branches.

Progress security advisory (AV26-552) - Canadian Centre for Cyber Security

Canadian Centre for Cyber Security issues advisory AV26-552

On June 5, 2026, the Cyber Centre issued advisory AV26-552 highlighting Progress security updates published between June 2 and 4. The advisory urged administrators to review Progress bulletins and apply patches for affected Sitefinity and LoadMaster versions.

Progress security advisory (AV26-552) - Canadian Centre for Cyber Security
Jun 2, 20269d ago

Progress receives multiple Sitefinity vulnerability reports

Several Sitefinity vulnerabilities, including CVE-2026-7201, CVE-2026-7312, and CVE-2026-7198, were received by security@progress.com on June 2, 2026. The reported issues included authorization bypass, improper access control, and exposure of plaintext credentials in Sitefinity web services.

CVE-2026-7201 - CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.