Progress Software security advisory (AV26-875)
Canada's Cyber Centre warns Progress Telerik UI for ASP.NET AJAX before 2026.3.812 is affected by path traversal and upload tampering flaws, urging updates.
The Canadian Centre for Cyber Security issued advisory AV26-875 on September 2, 2026, covering vulnerabilities in Progress Software Telerik UI for ASP.NET AJAX prior to version 2026.3.812. Two flaws are listed: CVE-2026-18672, a path traversal in the Telerik Web Forms RadImageEditor, and CVE-2026-19219, a DialogHandler UploadPaths tampering vulnerability. Administrators are encouraged to review the provided links and apply available updates.
- CVE-2026-18672: path traversal in Telerik Web Forms RadImageEditor
- CVE-2026-19219: DialogHandler UploadPaths tampering vulnerability
- Fixed in Telerik UI for ASP.NET AJAX version 2026.3.812
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18672 | Unauthenticated Path Traversal File Read in Telerik UI for ASP.NET AJAX RadImageEditor Progress Telerik UI for ASP.NET AJAX versions before 2026.3.812 contain a path traversal flaw (CWE-22) in the RadImageEditor control, caused by insufficient validation of client-supplied state. A remote, unauthenticated attacker (per CVSS: AV:N/AC:L/PR:N/UI:N) can submit manipulated state so that the control's image cache returns an attacker-influenced file. Successful abuse can expose the contents of files located outside the intended image directories, producing high confidentiality impact with no integrity or availability impact per the CVSS scoring. Any web application built on Telerik UI for ASP.NET AJAX that exposes RadImageEditor on a version older than 2026.3.812 is affected. There is no known exploitation, no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation within 30 days. Do: Upgrade Telerik UI for ASP.NET AJAX to version 2026.3.812 or later and verify the deployed Telerik.Web.UI assembly is no longer below that build. If an immediate upgrade is not possible, restrict access to pages hosting RadImageEditor (e.g., via authentication or network controls) and review image-cache requests that cause files to be returned from outside the configured image directories. Monitor the Progress advisory (AV26-875) for updates or added indicators. | 7.5 | <1% |
| large≈100,000+ deployments of the suite (only applications actually exposing RadImageEditor are vulnerable) | ||
| CVE-2026-19219 | Potential RCE in Progress Telerik UI for ASP.NET AJAX via dialog parameter tampering Progress Telerik UI for ASP.NET AJAX before v2026.3.812 provides insufficient integrity protection (CWE-345) on the dialog request parameters used by the RadEditor file browser, allowing those parameters to be altered. To exploit it, a network attacker must first have obtained certain application encryption key material used to protect the dialog parameters, which drives the high attack complexity; no privileges or user interaction are required. With tampered parameters, the attacker can control which folders the file browser reads from, writes to, and uploads into, enabling arbitrary file uploads (CWE-434) and potentially remote code execution by writing attacker-controlled files into sensitive or web-executable locations. Any web application built with Telerik UI for ASP.NET AJAX in versions prior to 2026.3.812 is affected. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days. Do: Upgrade Telerik UI for ASP.NET AJAX to v2026.3.812 or later. Audit how the Telerik dialog/encryption key material is configured for each application — rotate keys that may have been exposed, avoid reusing key material across applications, and treat leaked or shared keys as the main precondition for exploitation. For applications exposing RadEditor file browser dialogs, verify where uploads are written and whether uploaded files can execute (e.g., ASPX files in web-accessible directories), and restrict dialog access where possible. | 8.1 | <1% |
| largetens of thousands of internet-exposed ASP.NET web applications (exact install base not published) |
Full article68 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-875
Date: September 2, 2026
As of September 2, 2026, Progress Software is affected by vulnerabilities in the following product:
Telerik UI for ASP.NET AJAX
Prior to 2026.3.812
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Telerik Web Forms RadImageEditor Path Traversal Vulnerability (CVE-2026-18672)
Telerik Web Forms DialogHandler UploadPaths Tampering Vulnerability (CVE-2026-19219)
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/progress-software-security-advisory-av26-875