Security Vulnerabilities in Telerik UI lead to RCE

Telerik is informing licensed users of a series of flaws in Telerik UI for ASPdotNET AJAX that combine to lead to remote code execution in the server hosting the application. According to the notification, three components with server side events allow for unauthorized commands to be mistakenly processed. The Knowledge Base article will be published officially on July 22nd, but a draft can be found here.

From the notification:

Multiple vulnerabilities have been confirmed in the RadAsyncUpload, RadPersistenceManager and RadDockLayout components. When combined, these vulnerabilities can allow an unauthenticated remote attacker to achieve Remote Code Execution (RCE) on the server hosting the application.

The relevant CVEs are:

The affected components include:

  • RadAsyncUpload
    • affected versions: v2010.1.309 to v2026.2.519
    • fixed in 2026.2.708 (2026 Q2 SP1)
  • RadPersistenceManager, RadDockLayout
    • affected versions: v2013.1.220 to v2026.2.519
    • fixed in 2026.2.708 (2026 Q2 SP1)

There is a patch available from your Telerik Portal, but the recommendation is simply to upgrade to the latest full package version. Telerik documentation for the upgrade can be found here.

1 Like