PatchSiren cyber security CVE debrief
CVE-2026-13190 Progress Software CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.667Z and has not been modified since then. CVE-2026-13190 is a deserialization vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708. The vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution. Organizations using Progress Telerik UI for AJAX prior to v2026.2.708 should prioritize patching to prevent potential remote code execution attacks. The CVSS score for this vulnerability is 8.1, indicating a high severity. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.
- Vendor
- Progress Software
- Product
- Telerik UI for ASP.NET AJAX
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Organizations using Progress Telerik UI for AJAX prior to v2026.2.708 should prioritize patching to prevent potential remote code execution attacks.
Technical summary
CVE-2026-13190 is a deserialization vulnerability in the persistence utilities of Progress Telerik UI for AJAX. The vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution. The CVSS score for this vulnerability is 8.1, indicating a high severity.
Defensive priority
High priority should be given to patching Progress Telerik UI for AJAX installations to version 2026.2.708 or later to mitigate the deserialization vulnerability. Organizations should also review and update their inventory to ensure all instances of Progress Telerik UI for AJAX are patched and implement compensating controls such as monitoring and exception tracking to detect potential exploitation attempts. This vulnerability has a high CVSS score of 8.1, indicating a high severity, and organizations should take immediate action to patch affected systems. The deserialization vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution. Therefore, it is crucial to prioritize patching to prevent potential remote code execution attacks. The vulnerability affects Progress Telerik UI for AJAX prior to v2026.2.708, and organizations using these versions should prioritize patching to prevent potential attacks. The CVSS score for this vulnerability is 8.1, indicating a high severity, and organizations should take immediate action to patch affected systems. The vulnerability has been publicly disclosed, and defenders should be aware of the potential risks and take necessary precautions to protect their systems. The recommended actions for this vulnerability include applying the patch provided by Progress Telerik to update to version 2026.2.708 or later, reviewing and updating inventory to ensure all instances of Progress Telerik UI for AJAX are patched, and implementing compensating controls such as monitoring and exception tracking to detect potential exploitation attempts. The evidence notes and debrief sections provide additional context and guidance for defenders to prioritize patching and take necessary precautions to protect their systems. The technical summary and who should care sections also provide additional information on the vulnerability and its potential impact. The recommended actions section provides specific guidance for defenders to take action to mitigate the vulnerability. The defensive priority section provides guidance on the priority level for patching and mitigating the
Recommended defensive actions
- Apply the patch provided by Progress Telerik to update to version 2026.2.708 or later.
- Review and update inventory to ensure all instances of Progress Telerik UI for AJAX are patched.
- Implement compensating controls such as monitoring and exception tracking to detect potential exploitation attempts.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Progress Telerik has provided a knowledge base article on the vulnerability and the patch. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance. Additional information may be available through vendor support channels or security research sources.
Official resources
-
CVE-2026-13190 CVE record
CVE.org
-
CVE-2026-13190 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.667Z and has not been modified since then.