TopVuln

High-risk vulnerability digests

CVE-2026-6023

  • HIGH

Details

CVSS v3
8.1
NVD published
2026-04-22 08:16:13
EPSS
<0.1% probability · 16.2th percentile — 2026-05-12
Affected versions
Progress Telerik UI for AJAX 2024.4.114 through 2026.1.421
Summary
This vulnerability exists in the RadFilter control of Telerik UI for AJAX, which allows insecure deserialization of tampered client-side filter state. A remote attacker can exploit this flaw to achieve server-side remote code execution on the host application server.
Remediation
Upgrade Progress Telerik UI for AJAX to version 2026.1.421 or later to patch this vulnerability. Audit all running instances of Telerik UI in your environment to confirm they are running the patched version. Block untrusted access to endpoints that use the RadFilter control until patching is complete.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.