Multiple vulnerabilities in Progress Telerik (August 07, 2026)
Multiple vulnerabilities have been discovered in Progress Telerik. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities in Telerik allow remote code execution, denial of service, and data confidentiality breach.
- Who is affected
- Telerik deployments of unspecified versions are affected.
- Urgency
- High urgency; multiple RCE and DoS vectors present active attack surface.
- Action
- Apply patches from Progress for the affected Telerik products immediately upon availability.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Telerik
Get an email when a new Telerik advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0977/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-131870.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131900.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-149320.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-148650.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131860.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131830.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131850.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131810.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131920.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-131820.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-13187 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13190 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14932 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14865 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13186 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13183 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13185 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13181 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13192 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13182 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13188 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13189 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-13184 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-14932: In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's Char…nvd
- mediumCVE-2026-14865: In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control pro…nvd
- mediumCVE-2026-13192: In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content sub…nvd
- highCVE-2026-13190: In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the…nvd
- highCVE-2026-13189: In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the languag…nvd
- mediumCVE-2026-13188: In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may b…nvd
- highCVE-2026-13187: In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may …nvd
- highCVE-2026-13186: In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the …nvd
- highCVE-2026-13185: In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storag…nvd
- highCVE-2026-13184: In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashK…nvd
- highCVE-2026-13183: In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata process…nvd
- highCVE-2026-13182: In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing…nvd
Recent advisories for Progress Telerik
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-14932: In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's Char…nvd · 2026-07-22
- mediumCVE-2026-14865: In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control pro…nvd · 2026-07-22
- mediumCVE-2026-13192: In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content sub…nvd · 2026-07-22
- highCVE-2026-13190: In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the…nvd · 2026-07-22
- highCVE-2026-13189: In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the languag…nvd · 2026-07-22
- mediumCVE-2026-13188: In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may b…nvd · 2026-07-22
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in WordPress (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Google Chrome (August 07, 2026)2026-08-07
- unknownMultiple vulnerabilities in Debian LTS Linux kernel (August 07, 2026)2026-08-07