Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX
Progress Software has patched two vulnerabilities, including path traversal (CVE-2026-18672) and input tampering (CVE-2026-19219), in Telerik UI for ASP.NET AJAX versions prior to 2026.3.812.
CVE search metadata
CVE search record: CVE-2026-18672. Severity: high. CVSS: 7.5. KEV: no. Product: Telerik UI for ASP.NET AJAX (< 2026.3.812). Brief: Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX. Brief link: https://feed.craftedsignal.io/briefs/2026-09-progress-telerik-vulnerabilities/
CVE search record: CVE-2026-19219. Severity: high. CVSS: 8.1. KEV: no. Product: Telerik UI for ASP.NET AJAX (< 2026.3.812). Brief: Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX. Brief link: https://feed.craftedsignal.io/briefs/2026-09-progress-telerik-vulnerabilities/
Progress Software has released a security advisory concerning two vulnerabilities impacting Telerik UI for ASP.NET AJAX. The affected versions include all releases prior to 2026.3.812. The first vulnerability, CVE-2026-18672, is a path traversal flaw residing within the RadImageEditor component, which could allow an attacker to read or manipulate files on the underlying web server. The second vulnerability, CVE-2026-19219, involves improper handling of the DialogHandler UploadPaths configuration, potentially enabling unauthorized file uploads or system tampering. These vulnerabilities pose a significant risk to organizations hosting ASP.NET web applications that rely on the Telerik UI framework, as successful exploitation could lead to full system compromise or sensitive data exposure. Defenders should immediately identify all instances of Telerik UI for ASP.NET AJAX within their environment and upgrade to version 2026.3.812 or later to eliminate these attack vectors.
Impact
Successful exploitation of these vulnerabilities allows unauthorized remote actors to bypass security controls in ASP.NET web applications. CVE-2026-18672 could lead to arbitrary file read or write access on the host server, while CVE-2026-19219 could be leveraged to gain remote code execution or facilitate persistent backdoors via unauthorized file uploads. Organizations across all sectors utilizing vulnerable Progress Telerik components are at risk of data exfiltration and server takeover.
Recommendation
Prioritize the identification and patching of all web applications using Progress Telerik UI for ASP.NET AJAX.
- Upgrade Telerik UI for ASP.NET AJAX to version 2026.3.812 or later immediately to resolve CVE-2026-18672 and CVE-2026-19219.
- Audit web server logs for irregular POST requests to the DialogHandler and unusual file access patterns in the web root that may indicate attempted path traversal via RadImageEditor.
- Implement strict file system permissions for the web application user to minimize the impact if path traversal is successfully exploited.
Immediate actions
Upgrade Telerik UI for ASP.NET AJAX to 2026.3.812 or later
Mitigations
Upgrade Telerik UI for ASP.NET AJAX to 2026.3.812
CVE-2026-18672 and CVE-2026-19219