← All CVEs NewScan detects
critical

CVE-2026-13185

Telerik UI for ASP.NET AJAX deserialization of attacker-controlled cookie state in RadPersistenceManager / RadDockLayout -> unauthenticated remote code execution

Severity
critical
Affected product
Telerik UI for ASP.NET AJAX
Affected versions
Telerik UI for ASP.NET AJAX ≥ 2013.1.220, < 2026.2.708
Fixed in
Telerik UI for ASP.NET AJAX 2026.2.708
Added to NewScan
2026-09-07
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Telerik UI for ASP.NET AJAX from its response and reports this CVE when the detected version falls inside the affected range below.

Unauthenticated RCE where cookie-based persistence storage is in use. RadPersistenceManager / RadDockLayout, not RadAsyncUpload, so it is a separate chain from the 13181-13184 batch and has no public exploit. Version-match only: whether a given app uses cookie-based or file-based persistence storage is not observable from outside, so the row reports the vulnerable BUILD rather than asserting the configuration.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →