Warning: High-rated vulnerability in Progress Telerik UI for AJAX can lead to remote code execution, Patch Immediately!
ID: 25372d07-6e7c-5e88-aa6c-091976b30389
STIX ID: report--25372d07-6e7c-5e88-aa6c-091976b30389
Feed Name: CCB Advisories Feed
Threat Score
Progress Telerik UI for AJAX contains a high-severity deserialization vulnerability (CVE-2026-13185, CVSS 8.1) that enables remote code execution when applications use cookie-backed persistence (CookieStateStorageProvider or RadDockLayout set to Cookies). The Centre for Cybersecurity Belgium and Progress recommend immediate patching, disabling cookie persistence if patching is not possible, and increased monitoring; no active exploitation was reported as of 23 July 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
