Progress Software security advisory (AV26-875)
Serial number: AV26-875 Date: September 2, 2026 As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product: Telerik UI for ASP.NET AJAX Prior to 2026.3.812 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672) Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026-19219)
CSIRTS triage
- What
- Path traversal in RadImageEditor and parameter tampering in DialogHandler UploadPaths functionality.
- Who is affected
- Telerik UI for ASP.NET AJAX versions before 2026.3.812.
- Urgency
- Severity unknown; update should be applied as soon as available.
- Action
- Update Telerik UI for ASP.NET AJAX to version 2026.3.812 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Telerik UI for ASP.NET AJAX
Get an email when a new Telerik UI for ASP.NET AJAX advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/progress-software-security-advisory-av26-875
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18672 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-19219 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from Canadian Centre for Cyber Security
- unknownJFrog security advisory (AV26-867) – Update 12026-09-02
- unknownSonicWall security advisory (AV26-872) – Update 12026-09-02
- unknownGoogle security advisory (AV26-874)2026-09-02
- unknownHPE security advisory (AV26-873)2026-09-02
- unknown[Control systems] Schneider Electric security advisory (AV26-871)2026-09-02