Progress Sitefinity CMS — CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW)
cve · CVE-2026-7312
Coverage timeline
1
first 2026-06-04 → last 2026-06-04
Briefs
1
1 distinct
Sources cited
26
20 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-06-04CTI Daily Brief — 2026-06-04
Source distribution
- attack.mitre.org4 (15%)
- bleepingcomputer.com2 (8%)
- cert.ssi.gouv.fr2 (8%)
- nvd.nist.gov2 (8%)
- blog.talosintelligence.com1 (4%)
- cisa.gov1 (4%)
- dragos.com1 (4%)
- elastic.co1 (4%)
- other12 (46%)
External references
All cited sources (26)
- attack.mitre.orginlineSteal Application Access Tokenhttps://attack.mitre.org/techniques/T1528/
- attack.mitre.orginlineSteal Web Session Cookiehttps://attack.mitre.org/techniques/T1539/
- attack.mitre.orginlineWeb Session Cookiehttps://attack.mitre.org/techniques/T1550/004/
- attack.mitre.orginlineAdversary-in-the-Middlehttps://attack.mitre.org/techniques/T1557/
- bleepingcomputer.cominlineBleepingComputer 2026-05-05https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-15https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/
- blog.talosintelligence.cominlineCisco Talos 2026-05-05https://blog.talosintelligence.com/uat-8302/
- cert.ssi.gouv.frinlineCERT-FR, 2026-05-05https://www.cert.ssi.gouv.fr/
- cert.ssi.gouv.frinlineCERT-FR CERTFR-2026-AVI-0542https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0542/
- cisa.govinlineCISA KEV (added 2026-05-15)https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- dragos.cominlineDragos, 2026-05-06https://www.dragos.com/blog/ai-assisted-ics-attack-water-utility/
- elastic.coinlineElastic Security Labs 2026-05-07https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/
- huntress.cominlineHuntresshttps://www.huntress.com/blog/malspam-to-deskcvb-rat-delivery-chain-analysis
- kodemsecurity.cominlineKodem Security frames the AI-agent escalation pathhttps://www.kodemsecurity.com/resources/vm2-sandbox-escape-vulnerabilities-the-2026-cve-wave-turning-ai-agents-into-host-rce-vectors
- microsoft.cominlineMicrosoft Security Blog 2026-05-04https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
- msrc.microsoft.cominlineMSRC CVE-2026-42897https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897
- nvd.nist.govinlineNVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-5174
- nvd.nist.govinlineNVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-6023
- oasis.securityinlineOasis Security 2026-05-07https://www.oasis.security/blog/cline-kanban-websocket-hijack
- securitylabs.datadoghq.cominlineDatadog Security Labshttps://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/
- thehackernews.cominlineThe Hacker News 2026-05-04https://thehackernews.com/2026/05/progress-patches-critical-moveit.html
- upguard.cominlineUpGuardhttps://www.upguard.com/news/world-food-programme-data-breach-2026-06-02
- wid.cert-bund.deinlineBSI WID-SEC-2026-1583https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1583
- wiz.ioinlineWiz Researchhttps://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc
- zerodayinitiative.cominlineZero Day Initiative, 2026-05-15https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results
Items in briefs about Progress Sitefinity CMS — CWE-522 Insufficiently Protected Credentials (Sitefinity Insight credential disclosure, gated on Insight integration/non-default config); CVSS 10.0 per NVD; BSI WID-SEC-2026-1783; evaluated 2026-06-04, dropped to §7 (no fetchable vendor primary, no ITW)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.