PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
← All CVEs
CVE WatchAug 6, 2026

CVE-2026-13182

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid

CVSS

7.5

High

EPSS

0.3%

p25

KEV

Exploit Today

7

0-100

Published: Jul 22, 2026 · Last modified: Aug 6, 2026 · CWE-209

EPSS · 30d
0.3%EPSS · 30 days0.5%
2026-08-162026-09-12
Technical description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-663066.5 MED
42.3%
13Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.6d
CVE-2026-696845.5 MED
39.3%
12Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.5d
CVE-2026-695525.7 MED
57.5%
17Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.5d
CVE-2026-692945.5 MED
28.1%
8Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.5d
CVE-2026-688865.5 MED
39.3%
12Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.5d
CVE-2026-673836.5 MED
59.4%
18Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.5d