Applied Cybernetics Group
Threat intel → detection pipeline
Friday, September 18, 2026
Data as of 13:09 UTC

known ransomware use

Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

Added to KEV
2023-01-26
Federal due date
2023-02-16
Vendor
Telerik
Product
User Interface (UI) for ASP.NET AJAX
EPSS
99.5th percentile (score 0.777, as of 2026-09-16)
NVD CVSS v3.1
9.8 (CRITICAL)
Ransomware use
Known
Upstream
https://nvd.nist.gov/vuln/detail/CVE-2017-11357

CISA short description

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Required action

Apply updates per vendor instructions.

NVD description

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

EPSS percentile is the FIRST.org exploit-probability ranking as of the date noted above; it moves daily. CVSS reflects NVD's analysis at time of publication.