In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
| Vendor | Product | Versions |
|---|---|---|
| progress | telerik ui for asp.net ajax | 2011.2.712 |
Updated severity from HIGH to CRITICAL, adjusted CVSS estimate to 9.0, and corrected affected version to 2026.2.707 (prior to patch 2026.2.708).
Initial creation