{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/telerik-ui-for-asp.net-ajax--2026.3.812/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:progress:telerik_ui_for_asp_net_ajax:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18672"},{"cvss":8.1,"id":"CVE-2026-19219"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Telerik UI for ASP.NET AJAX (\u003c 2026.3.812)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","patch-management"],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eProgress Software has released a security advisory concerning two vulnerabilities impacting Telerik UI for ASP.NET AJAX. The affected versions include all releases prior to 2026.3.812. The first vulnerability, CVE-2026-18672, is a path traversal flaw residing within the RadImageEditor component, which could allow an attacker to read or manipulate files on the underlying web server. The second vulnerability, CVE-2026-19219, involves improper handling of the DialogHandler UploadPaths configuration, potentially enabling unauthorized file uploads or system tampering. These vulnerabilities pose a significant risk to organizations hosting ASP.NET web applications that rely on the Telerik UI framework, as successful exploitation could lead to full system compromise or sensitive data exposure. Defenders should immediately identify all instances of Telerik UI for ASP.NET AJAX within their environment and upgrade to version 2026.3.812 or later to eliminate these attack vectors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows unauthorized remote actors to bypass security controls in ASP.NET web applications. CVE-2026-18672 could lead to arbitrary file read or write access on the host server, while CVE-2026-19219 could be leveraged to gain remote code execution or facilitate persistent backdoors via unauthorized file uploads. Organizations across all sectors utilizing vulnerable Progress Telerik components are at risk of data exfiltration and server takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all web applications using Progress Telerik UI for ASP.NET AJAX.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Telerik UI for ASP.NET AJAX to version 2026.3.812 or later immediately to resolve CVE-2026-18672 and CVE-2026-19219.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for irregular POST requests to the DialogHandler and unusual file access patterns in the web root that may indicate attempted path traversal via RadImageEditor.\u003c/li\u003e\n\u003cli\u003eImplement strict file system permissions for the web application user to minimize the impact if path traversal is successfully exploited.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T00:08:03Z","date_published":"2026-09-03T00:08:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-progress-telerik-vulnerabilities/","summary":"Progress Software has patched two vulnerabilities, including path traversal (CVE-2026-18672) and input tampering (CVE-2026-19219), in Telerik UI for ASP.NET AJAX versions prior to 2026.3.812.","title":"Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX","url":"https://feed.craftedsignal.io/briefs/2026-09-progress-telerik-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Telerik UI for ASP.NET AJAX (\u003c 2026.3.812)","version":"https://jsonfeed.org/version/1.1"}