In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Telerik_ui_for_asp.net_ajax | Progress | 2011.2712 (including) | 2026.2.708 (excluding) |