Disclosure summary
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
CISA remediation guidance
Apply updates per vendor instructions.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
ASEC BLOG · RSS-a8a84177f061714c1ff89eff7b952d4adb1
Open original source · Updated Sep 27, 2026
Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2021-11-03T00:00:00-04:00
MODIFIED 2021-11-03T00:00:00-04:00
INGESTED 2026-10-06T11:42:59-04:00