Progress released security updates for Sitefinity CMS, Sitefinity Insight, and Kemp LoadMaster, with the most urgent attention on multiple severe Sitefinity web-service vulnerabilities affecting versions from 8.0 through 15.4. The Canadian Centre for Cyber Security flagged the vendor advisories and urged administrators to review Progress bulletins and apply patches. Among the Sitefinity issues, CVE-2026-7312 carries a CVSS 10.0 rating and can let an unauthenticated attacker obtain plaintext credentials used for Sitefinity Insight connections when that integration is enabled in a non-default configuration, while CVE-2026-7198 is rated CVSS 9.8 and allows unauthenticated access to restricted content in affected 15.4 deployments.
Additional Sitefinity flaws include CVE-2026-7201, an authorization bypass that can let an authenticated low-privilege user modify other users' account properties, and CVE-2026-7313, which exposes Insight credentials to authenticated back-end users under specific configurations. Progress published patched releases including 15.4.8630, 15.3.8531, 15.2.8441, 15.1.8335, 15.0.8234, 14.4.8152, and 13.3.7652, and warned that delaying remediation leaves OData and related web services open to unauthorized exploitation. The broader advisory set also includes two vulnerabilities affecting Progress Kemp LoadMaster.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-09, ZDI disclosed CVE-2026-8037, a critical unauthenticated remote code execution flaw in Progress Kemp LoadMaster's accessv2 endpoint involving the apiuser parameter. The advisory said Progress released an update to remediate the issue, and credited Syed Ibrahim Ahmed of TrendAI Research for the finding.
Between June 2 and June 4, 2026, Progress published security updates addressing critical vulnerabilities in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster. The updates covered multiple Sitefinity CVEs and two LoadMaster CVEs, with patched Sitefinity releases issued for supported branches.
On June 5, 2026, the Cyber Centre issued advisory AV26-552 highlighting Progress security updates published between June 2 and 4. The advisory urged administrators to review Progress bulletins and apply patches for affected Sitefinity and LoadMaster versions.
Several Sitefinity vulnerabilities, including CVE-2026-7201, CVE-2026-7312, and CVE-2026-7198, were received by security@progress.com on June 2, 2026. The reported issues included authorization bypass, improper access control, and exposure of plaintext credentials in Sitefinity web services.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.