Remote Code Execution Vulnerability in Telerik UI for AJAX
CVE-2026-13185
8.1HIGH
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 22 July 2026
What is CVE-2026-13185?
Progress Telerik UI for AJAX versions prior to v2026.2.708 suffer from a vulnerability that allows applications utilizing cookie-based storage in RadPersistenceManager or RadDockLayout to inadvertently deserialize attacker-controlled cookie content. This flaw could enable unauthenticated attackers to execute arbitrary code remotely, highlighting the need for organizations to update to the latest version to mitigate potential risks.
Affected Version(s)
Telerik UI for ASP.NET AJAX 2013.1.220 < 2026.2.708