Deserialization Vulnerability in Progress Telerik UI for AJAX
CVE-2026-13190
8.1HIGH
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 22 July 2026
What is CVE-2026-13190?
A vulnerability in the persistence utilities of Progress Telerik UI for AJAX prior to version 2026.2.708 allows for unsafe type instantiation. An attacker can exploit this by manipulating the persisted state, which may lead to remote code execution. Proper security measures and updates are advised to mitigate risks associated with this issue.
Affected Version(s)
Telerik UI for ASP.NET AJAX 2011.2.712 < 2026.2.708