In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
| Vendor | Product | Versions |
|---|---|---|
| progress | telerik ui for asp.net ajax | 2013.1.220 |
Updated severity from HIGH to CRITICAL, adjusted CVSS estimate to 9.0, and corrected affected versions to include up to 2026.2.707 (not just 2013.1.220)
Initial creation