{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/telerik-ui-for-asp.net-ajax/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-13181"},{"cvss":6.5,"id":"CVE-2026-13192"},{"cvss":5.3,"id":"CVE-2026-14865"},{"cvss":6.5,"id":"CVE-2026-14932"},{"cvss":7.5,"id":"CVE-2026-13183"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Telerik UI for ASP.NET AJAX"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","rce","srf"],"_cs_type":"advisory","_cs_vendors":["Progress"],"content_html":"\u003cp\u003eProgress has disclosed thirteen critical security vulnerabilities affecting Telerik UI for ASP.NET AJAX versions prior to 2026.2.708 (2026 Q2 SP1). These flaws, identified as CVE-2026-13181 through CVE-2026-13192, and CVE-2026-14865 and CVE-2026-14932, encompass a wide range of attack vectors including insecure deserialization, path traversal, XML External Entity (XXE) injection, and Server-Side Request Forgery (SSRF).\u003c/p\u003e\n\u003cp\u003eThe vulnerabilities affect multiple components of the Telerik framework, such as RadAsyncUpload, RadEditor, and the framework's persistence and dialog handlers. Successful exploitation allows unauthenticated attackers to achieve remote code execution, perform unauthorized file reads, bypass security policies, or cause denial of service. Given the broad surface area and the potential for full system compromise via deserialization chains, organizations must prioritize patching all Telerik UI implementations to version 2026.2.708 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to full system compromise, exfiltration of sensitive data, and persistent access within the affected infrastructure. Organizations using Telerik UI for public-facing web applications are at significant risk of unauthenticated remote exploitation. The combination of RCE and file-read capabilities poses a high risk to both internal data integrity and the availability of business-critical applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade all instances of Telerik UI for ASP.NET AJAX to version 2026.2.708 or later.\u003c/li\u003e\n\u003cli\u003eReview web server logs for requests targeting Telerik handlers (e.g., \u003ccode\u003eRadAsyncUpload\u003c/code\u003e, \u003ccode\u003eDialogHandler\u003c/code\u003e, \u003ccode\u003eRadEditor\u003c/code\u003e) that contain serialized objects, path traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e), or unexpected XML entities.\u003c/li\u003e\n\u003cli\u003eRestrict network access to Telerik management endpoints and file-upload handlers to trusted internal subnets where possible.\u003c/li\u003e\n\u003cli\u003eUse vulnerability scanning tools to inventory all applications utilizing vulnerable versions of the Telerik DLLs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-07T15:21:18Z","date_published":"2026-08-07T15:21:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-progress-telerik-vulnerabilities/","summary":"Progress Telerik UI for ASP.NET AJAX is affected by a suite of thirteen critical vulnerabilities, including insecure deserialization, path traversal, XXE, and SSRF, which collectively enable remote code execution and data theft.","title":"Multiple Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX","url":"https://feed.craftedsignal.io/briefs/2026-08-progress-telerik-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Telerik UI for ASP.NET AJAX","version":"https://jsonfeed.org/version/1.1"}