<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aprogresstelerik_ui_for_asp.net_ajax/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 07 Aug 2026 15:21:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aprogresstelerik_ui_for_asp.net_ajax/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX</title><link>https://feed.craftedsignal.io/briefs/2026-08-progress-telerik-vulnerabilities/</link><pubDate>Fri, 07 Aug 2026 15:21:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-progress-telerik-vulnerabilities/</guid><description>Progress Telerik UI for ASP.NET AJAX is affected by a suite of thirteen critical vulnerabilities, including insecure deserialization, path traversal, XXE, and SSRF, which collectively enable remote code execution and data theft.</description><content:encoded><![CDATA[<p>Progress has disclosed thirteen critical security vulnerabilities affecting Telerik UI for ASP.NET AJAX versions prior to 2026.2.708 (2026 Q2 SP1). These flaws, identified as CVE-2026-13181 through CVE-2026-13192, and CVE-2026-14865 and CVE-2026-14932, encompass a wide range of attack vectors including insecure deserialization, path traversal, XML External Entity (XXE) injection, and Server-Side Request Forgery (SSRF).</p>
<p>The vulnerabilities affect multiple components of the Telerik framework, such as RadAsyncUpload, RadEditor, and the framework's persistence and dialog handlers. Successful exploitation allows unauthenticated attackers to achieve remote code execution, perform unauthorized file reads, bypass security policies, or cause denial of service. Given the broad surface area and the potential for full system compromise via deserialization chains, organizations must prioritize patching all Telerik UI implementations to version 2026.2.708 or later.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities can lead to full system compromise, exfiltration of sensitive data, and persistent access within the affected infrastructure. Organizations using Telerik UI for public-facing web applications are at significant risk of unauthenticated remote exploitation. The combination of RCE and file-read capabilities poses a high risk to both internal data integrity and the availability of business-critical applications.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade all instances of Telerik UI for ASP.NET AJAX to version 2026.2.708 or later.</li>
<li>Review web server logs for requests targeting Telerik handlers (e.g., <code>RadAsyncUpload</code>, <code>DialogHandler</code>, <code>RadEditor</code>) that contain serialized objects, path traversal sequences (e.g., <code>../</code>), or unexpected XML entities.</li>
<li>Restrict network access to Telerik management endpoints and file-upload handlers to trusted internal subnets where possible.</li>
<li>Use vulnerability scanning tools to inventory all applications utilizing vulnerable versions of the Telerik DLLs.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>rce</category><category>srf</category></item></channel></rss>