Progress Telerik UI patches multiple RCE flaws
Progress patched 13 vulnerabilities in Telerik UI for AJAX, several allowing remote code execution, DoS, or data exposure; no active exploitation reported.
ANSSI (CERT-FR) issued an advisory covering multiple vulnerabilities in Progress Telerik UI for AJAX affecting versions prior to 2026.2.708 (2026 Q2 SP1). The flaws span a range of weaknesses including insecure deserialization chains, padding and timing oracles, path traversal, hardcoded key exposure, SSRF via PDF export, XXE injection, and type-tampering issues across various Telerik components (RadAsyncUpload, DialogHandler, SpellChecker, Persistence Framework, RadListBox, RadChart).
Collectively, exploitation of these vulnerabilities could allow an attacker to achieve remote code execution, cause denial of service, compromise data confidentiality and integrity, bypass security policies, or perform server-side request forgery. Fourteen distinct CVEs were disclosed by Progress on 22 July 2026, indicating a broad review and hardening effort across the Telerik AJAX component suite rather than a single isolated flaw.
There is no indication in the advisory of active exploitation in the wild. Organizations using affected Telerik UI for AJAX versions should apply the vendor-provided patches referenced in Progress's security bulletins as soon as feasible, given the number and severity of the underlying issues, particularly those enabling remote code execution.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0977
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free