Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover
Security firm TantoSec has released a proof-of-concept exploit chain targeting Telerik UI for ASP.NET AJAX, a widely used web development component. The chain, which combines a padding-oracle weakness in AES-CBC encryption with an unguarded type-resolution flaw (CVE-2026-13181, rated 8.1 high severity), can allow an attacker without any login credentials to run malicious code on a vulnerable server. Progress Software, the vendor, patched the underlying issues back in July with version 2026.2.708.
What has changed is that TantoSec has now published a detailed technical write-up alongside a ready-to-use command-line tool and two payloads, one that writes a web shell to disk and one that runs entirely in memory. This gives attackers a complete, public attack path where previously only isolated pieces of the vulnerability were known. There are currently no confirmed reports of this exploit being used in real attacks.
Importantly, exploitation only works under specific conditions: the application must use the RadAsyncUpload control with a server-side handler reading upload results, and it must be configured with an explicit, non-default encryption key, ironically a setting Telerik itself recommends as a hardening measure. Versions from 2010.1.309 through 2026.2.519 are affected, with 2026.2.708 and later fixed.
Key Takeaway: Australian businesses using Telerik UI for ASP.NET AJAX should update to version 2026.2.708 or later immediately and review whether their RadAsyncUpload configuration matches the vulnerable setup described by researchers.