Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4442 articles · 179515 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-13184PATCHED
progress · telerik ui for asp.net ajax

RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX

Description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

Affected Products

VendorProductVersions
progresstelerik ui for asp.net ajax2010.1.309

References

  • https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-unauth-deserialization-chain-cve-2026-13184(vendor-advisory)

Related News (1 articles)

Tier C
VulDB8h ago
CVE-2026-13184 | Progress Telerik UI for ASP.NET AJAX up to 2026.2.707 Upload default key
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.708
CWECWE-321
PublishedJul 22, 2026
Last enriched7h agov2
Trending Score36
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-8037EXPKEV
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Trending: 91
HIGHCVE-2026-13189
SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 36
HIGHCVE-2026-13182
RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 36
HIGHCVE-2026-13183
RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Trending: 36
MEDIUMCVE-2026-14865
XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
Trending: 32

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: affectedVersions, cweIds
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 7h ago
v2Tier C7h ago

Added affected version 2026.2.707 and identified CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) in addition to existing CWE-321.

affectedVersionscweIds
via VulDB
v18h ago

Initial creation