Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4876 articles · 221243 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-13184PATCHED
progress · telerik_ui_for_asp.net_ajax

RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX

Description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

Affected Products

VendorProductVersions
progresstelerik_ui_for_asp.net_ajax2010.1.309

References

  • https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-unauth-deserialization-chain-cve-2026-13184(vendor-advisory)

Related News (3 articles)

Tier D
The Hacker News15d ago
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
→ No new info (linked only)
Tier B
CERT-FR47d ago
Multiples vulnérabilités dans Progress Telerik (07 août 2026)
→ No new info (linked only)
Tier C
VulDB62d ago
CVE-2026-13184 | Progress Telerik UI for ASP.NET AJAX up to 2026.2.707 Upload default key
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.708
CWECWE-321
PublishedJul 22, 2026
Last enriched62d agov2
Trending Score9
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-80462
Privilege Escalation in Progress Chef Automate
Trending: 12
HIGHCVE-2026-13183
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 9
HIGHCVE-2026-19219
DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 5
HIGHCVE-2026-18672
RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 5
HIGHCVE-2026-16139
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: affectedVersions, cweIds
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 62d ago
v2Tier C62d ago

Added affected version 2026.2.707 and identified CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) in addition to existing CWE-321.

affectedVersionscweIds
via VulDB
v162d ago

Initial creation