Progress Software Patched Telerik Fiddler Classic Flaws

The update resolves four security vulnerabilities that affected the web debugging proxy on Windows systems.

Updated on Oct. 7, 2026 in Cybersecurity

Bold flat-color editorial illustration featuring a large brass padlock locked onto a thick steel data cable, symbolizing digital security.
Progress Software has released an update for Telerik Fiddler Classic to address four security vulnerabilities identified by the NATO Cyber Security Centre. AI Illustration. Upload story photo >

Live Poll

Do you trust that software providers will patch security vulnerabilities in a timely manner?

Progress Software has released an update for Telerik Fiddler Classic to address four distinct security vulnerabilities. The flaws were identified and disclosed to the company by the NATO Cyber Security Centre.

Why it matters

These vulnerabilities, which range in severity, involved weaknesses in HTTP request handling, certificate installation, and executable verification. Fixing these gaps is critical to maintaining the security of development and debugging environments.

The patched version 6.0.20262.10021 resolves vulnerabilities including CVE-2026-77805, which carries a CVSS score of 7.9. Other fixed issues include CVE-2026-77804 at 6.6, CVE-2026-77802 at 6.3, and CVE-2026-77803 at 3.6.

The players

Progress Software

Progress Software is an American public company that provides software for developing and deploying business applications.

NATO Cyber Security Centre

The NATO Cyber Security Centre is the organization responsible for providing specialized cyber defense support and threat intelligence to NATO members.

The details

Users running versions of Telerik Fiddler Classic prior to 6.0.20262.10021 are urged to upgrade to the latest release to secure their Windows environments. For users unable to patch immediately, the company has provided temporary manual mitigation steps.

Timeline

  1. Progress released the fixed Fiddler Classic version on October 5, 2026.

The Tech Race

The vulnerabilities patched in this update are not currently listed in the CISA Known Exploited Vulnerabilities catalog, marking them as proactive security fixes. This aligns with a broader industry trend of vendors addressing security debt in legacy debugging tools before they become active attack vectors.

Developers and IT professionals should immediately update their Fiddler Classic installation to version 6.0.20262.10021 to ensure their local Windows development environment remains secure. If an immediate update is not feasible, administrators should implement the manual mitigation steps recommended by the developer.

The takeaway

Proactive patching of debugging tools is essential to prevent potential unauthorized access to developer workstations. Organizations should prioritize updating software tools regularly even when vulnerabilities are not yet known to be exploited in the wild.

Further reading

For more information on current digital threats, visit our Cybersecurity section.

Source note: This article includes information reported by ESecurityPlanet.

Live Poll

Do you trust that software providers will patch security vulnerabilities in a timely manner?