CVE-2026-13184
Multiple vulnerabilities have been discovered in Progress Telerik. Some of them allow an attacker to cause remote arbitrary code execution, remote denial of service and breach of data confidentiality.
CSIRTS triage
- What
- Multiple vulnerabilities in Telerik allow remote code execution, denial of service, and data confidentiality breach.
- Who is affected
- Telerik deployments of unspecified versions are affected.
- Urgency
- High urgency; multiple RCE and DoS vectors present active attack surface.
- Action
- Apply patches from Progress for the affected Telerik products immediately upon availability.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-13184
Get an email if CVE-2026-13184 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Advisory coverage (2)
- unknownMultiple vulnerabilities in Progress Telerik (August 07, 2026)cert-fr-avis · 2026-08-07
- highCVE-2026-13184: In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashK…nvd · 2026-07-22
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-13184)