logo

Warning: High-rated vulnerability in Progress Telerik UI for AJAX can lead to remote code execution, Patch Immediately!

ID: 25372d07-6e7c-5e88-aa6c-091976b30389

STIX ID: report--25372d07-6e7c-5e88-aa6c-091976b30389

Feed Name: CCB Advisories Feed

Threat Score
72/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

Progress Telerik UI for AJAX contains a high-severity deserialization vulnerability (CVE-2026-13185, CVSS 8.1) that enables remote code execution when applications use cookie-backed persistence (CookieStateStorageProvider or RadDockLayout set to Cookies). The Centre for Cybersecurity Belgium and Progress recommend immediate patching, disabling cookie persistence if patching is not possible, and increased monitoring; no active exploitation was reported as of 23 July 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.