CVE-2026-13185
Progress Software Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
- CVSS
- 8.1
- EPSS
- 0.45% 37.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.22