CVE-2026-6023
8.1Progress Software · Telerik UI for ASP.NET AJAX
Progress Telerik UI for ASP.NET AJAX is vulnerable to insecure deserialization in the RadFilter control, which may allow unauthenticated remote code execution.
Executive summary
A critical insecure deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allows unauthenticated attackers to achieve remote code execution.
Vulnerability
The RadFilter control fails to properly validate serialized data when restoring filter state. This flaw allows an unauthenticated attacker to inject malicious payloads into the state, resulting in remote code execution on the underlying server.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high potential for severe compromise. Successful exploitation grants an attacker full control over the application server, leading to potential data exfiltration, total loss of system integrity, and significant operational downtime.
Remediation
Immediate Action: Upgrade all instances of Progress Telerik UI for ASP.NET AJAX to version 2026.1.421 or later as specified by the vendor security advisory.
Proactive Monitoring: Review web application logs for suspicious serialized objects or unexpected input patterns targeting the RadFilter endpoint.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block malicious deserialization attempts or anomalous traffic patterns targeting Telerik controls.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of remote code execution, organizations must prioritize patching their Telerik environments. Failure to update the affected library leaves the server exposed to unauthorized command execution. Apply the vendor-provided fix immediately to eliminate this critical attack vector.