PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13190 Progress Software CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.667Z and has not been modified since then. CVE-2026-13190 is a deserialization vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708. The vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution. Organizations using Progress Telerik UI for AJAX prior to v2026.2.708 should prioritize patching to prevent potential remote code execution attacks. The CVSS score for this vulnerability is 8.1, indicating a high severity. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance.

Vendor
Progress Software
Product
Telerik UI for ASP.NET AJAX
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Organizations using Progress Telerik UI for AJAX prior to v2026.2.708 should prioritize patching to prevent potential remote code execution attacks.

Technical summary

CVE-2026-13190 is a deserialization vulnerability in the persistence utilities of Progress Telerik UI for AJAX. The vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution. The CVSS score for this vulnerability is 8.1, indicating a high severity.

Defensive priority

High priority should be given to patching Progress Telerik UI for AJAX installations to version 2026.2.708 or later to mitigate the deserialization vulnerability. Organizations should also review and update their inventory to ensure all instances of Progress Telerik UI for AJAX are patched and implement compensating controls such as monitoring and exception tracking to detect potential exploitation attempts. This vulnerability has a high CVSS score of 8.1, indicating a high severity, and organizations should take immediate action to patch affected systems. The deserialization vulnerability allows for unsafe type instantiation from attacker-influenced persisted state, potentially leading to remote code execution. Therefore, it is crucial to prioritize patching to prevent potential remote code execution attacks. The vulnerability affects Progress Telerik UI for AJAX prior to v2026.2.708, and organizations using these versions should prioritize patching to prevent potential attacks. The CVSS score for this vulnerability is 8.1, indicating a high severity, and organizations should take immediate action to patch affected systems. The vulnerability has been publicly disclosed, and defenders should be aware of the potential risks and take necessary precautions to protect their systems. The recommended actions for this vulnerability include applying the patch provided by Progress Telerik to update to version 2026.2.708 or later, reviewing and updating inventory to ensure all instances of Progress Telerik UI for AJAX are patched, and implementing compensating controls such as monitoring and exception tracking to detect potential exploitation attempts. The evidence notes and debrief sections provide additional context and guidance for defenders to prioritize patching and take necessary precautions to protect their systems. The technical summary and who should care sections also provide additional information on the vulnerability and its potential impact. The recommended actions section provides specific guidance for defenders to take action to mitigate the vulnerability. The defensive priority section provides guidance on the priority level for patching and mitigating the

Recommended defensive actions

  • Apply the patch provided by Progress Telerik to update to version 2026.2.708 or later.
  • Review and update inventory to ensure all instances of Progress Telerik UI for AJAX are patched.
  • Implement compensating controls such as monitoring and exception tracking to detect potential exploitation attempts.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Progress Telerik has provided a knowledge base article on the vulnerability and the patch. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability. Defenders should verify affected deployments and review official advisories for specific guidance. Additional information may be available through vendor support channels or security research sources.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:14.667Z and has not been modified since then.