CVE-2026-13182
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid
CVSS
7.5
High
EPSS
0.3%
p25
KEV
—
Exploit Today
7
0-100
Published: Jul 22, 2026 · Last modified: Aug 6, 2026 · CWE-209
0.3%EPSS · 30 days0.5%
2026-08-162026-09-12
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-663066.5 MED42.3%
——13Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.6dCVE-2026-696845.5 MED39.3%
——12Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.5dCVE-2026-695525.7 MED57.5%
——17Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.5dCVE-2026-692945.5 MED28.1%
——8Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.5dCVE-2026-688865.5 MED39.3%
——12Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.5dCVE-2026-673836.5 MED59.4%
——18Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.5d