Sitefinity® CMS 15.4 Update is Here—Built for What's Next

Learn More

generic-page

Sitefinity Release Notes

Sitefinity CMS 15.4.8638 (Product Update)

September 17, 2026

What's new

  • Connect external MCP servers
    In addition to the built-in tools provided through the Sitefinity MCP Server, Sitefinity AI agents can now use tools provided through external MCP servers. Tools exposed by external MCP servers enable the AI agents to safely perform AI-driven actions in Sitefinity CMS backend and interact with external systems. You can connect an external MCP server using the administrative backend UI and Sitefinity CMS lists the tools exposed by this server. Learn more...

  • Tool management capability is introduced
    New capability is introduced that allows you to manage the state of built-in Sitefinity tools and the tools exposed by external MCP servers. In your Sitefinity CMS backend, all available MCP tools are managed independently from the AI agents. For the Sitefinity MCP server and every connected external MCP server, you can configure the state of their respective tools individually. Learn more...

  • AI permissions model is introduced
    Site administrators can now manage permissions for configuring and using Sitefinity AI capabilities. A dedicated permissions model for AI usage helps address key governance needs:

    • Controlled and low-risk AI adoption
    • Gradual rollout of Sitefinity AI capabilities
    • Effective governance of AI usage based on user responsibilities
    • Legal compliance

    Learn more...

  • Global Hybrid Search tool is now available in Sitefinity MCP server
    The tool performs hybrid search, powered by Progress Agentic RAG, on all content types in Sitefinity CMS backend. NOTE: The built-in Agentic RAG System connection must be configured as the hybrid backend search relies on the system connection. Learn more...

  • Support added for new search filter operators: "isempty" and "isnotempty"
    The new filter operators work with Azure AI Search and Elasticsearch services, and apply only to collection type properties - such as classification fields.
    Learn more...(ASP.NET Core), Learn more...(Next.js)

What's fixed

  • ASP.NET Core Renderer: Login widget crashes with relative ReturnUrl query parameter (597682)
  • ASP.NET Core Renderer: Choice values containing commas cause response to appear empty (599661)
  • Next.js Renderer: Cannot read properties of undefined (reading 'IsSubFolder') error when requesting new web service endpoint (599922)
  • Edits on child page templates invalidates the cache on parent page template and all pages using these page templates (598941)
  • MVC: Video widget renders video URL as absolute (http) instead of 'https' under SSL offloading (598067)
  • LifecycleExtensions generates COUNT(*) instead of NOT EXISTS (599573)
  • HeadTagContent entirely removed when it contains "description" (substring match bug in PageHelper.RemoveMetaControlFromPage) (596870)
  • Unsynchronized HashSet in PagesConfig.GetNotAllowedExtensions corrupts under concurrent requests (600074)
  • Image libraries: Thumbs view does not load all items at wide viewports (597973)
  • Documents: Using chunk upload with Azure Blob Storage sets application/octet-stream on the uploaded media (596919)
  • Libraries: Media uploads over 100 MB fail with ODataException after AspNet.OData 7.8.0 upgrade (600308)
  • Dynamic content: Related items from a different provider are not displayed when selecting related data items (599580)
  • Site Sync: Sync cannot start after editing Scheduled sync (600266)
  • Site Sync: "This site only" scope setting lost when syncing through intermediate environment in multi-environment Site Sync setup (597953)
  • AI Assistant widget with Agentic RAG connector incorrect filter applied by current site and culture (599634)
  • AI search results, AI answer widgets with Agentic RAG connector incorrect filter applied by current site and culture (598247)
  • Web Service access restriction is case sensitive on the URL (599924)
  • BlackDuck scan reports Medium scored BDSAs in Bootstrap 5 dependencies (596164)
  • Dynamic module named "Users" cannot be managed in AdminApp (594165)
  • Output Cache: When upgrading Sitefinity CMS, NullReferenceException occurs in OutputCacheHelper.GenerateVariationsKey (599960)
  • NullReferenceException is thrown in PageSiteNodeWrapper.get_DateCreated() on pages with MVC action URL segments, when Sitefinity Insight tracking is enabled (596006)
  • Content recommendation widget does not show Insight recommendation for dynamic types (592877)
  • DECSystemStatusRetriever throws errors if an obsolete API key is used (598609)

Third-party libraries update

  • System.Text.Json -> 10.0.6

API and breaking changes

  • Removed multiple properties of the AiAgent class as they are now resolved dynamically at runtime. Impact: The AiAgent class is intended for internal use by Sitefinity CMS backend interface and is not part of the public API. If you have referenced the AiAgent class in custom code, remove those references as this class is not supported for external use.

  • Removed the TypeAndFieldsModel class.  TypeAndFieldsModel supported the content type and field configuration previously exposed on AiAgent, which is now resolved dynamically.
    Impact: Same as above.

  • Removed the LibrariesManager.StoreCustomThumbnail method.
    Impact: Use ThumbnailsOperationProvider.SaveCustomImageThumbnail method instead.

    Learn more...

CTA-banner
Progress Sitefinity

Meaningful engagement, elevated experiences delivered with ease.
Set your sites on Sitefinity.