RW
RiskWire Real-time vulnerability intelligence
This week Pricing Live dashboard
Critical 9.8 KEV + Ransomware

CVE-2019-18935

Exploitation of CVE-2019-18935 in Telerik UI for ASP.NET AJAX

Vendor / product: Telerik UI for ASP.NET AJAX
Event date: 2020-05-01
Public PoC: Yes
First tracked by RiskWire: 2026-09-28

CISA KEV catalog

Added to KEV
Federal remediation due
2022-05-03 (1609 days overdue)
Ransomware campaign use
Known
CISA description
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
Required action
Apply updates per vendor instructions.

Named threat actors

Blue Mockingbird

Sources & citations (1)

References

See CVE-2019-18935 in context

RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.

Book a 20-min demo →