Threat Intelligence

Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover

The Hacker News · 7 Sept 2026
Key Takeaway Australian businesses using Telerik UI for ASP.NET AJAX should update to version 2026.2.708 or later immediately and review whether their RadAsyncUpload configuration matches the vulnerable setup described by researchers.

Security firm TantoSec has released a proof-of-concept exploit chain targeting Telerik UI for ASP.NET AJAX, a widely used web development component. The chain, which combines a padding-oracle weakness in AES-CBC encryption with an unguarded type-resolution flaw (CVE-2026-13181, rated 8.1 high severity), can allow an attacker without any login credentials to run malicious code on a vulnerable server. Progress Software, the vendor, patched the underlying issues back in July with version 2026.2.708.

What has changed is that TantoSec has now published a detailed technical write-up alongside a ready-to-use command-line tool and two payloads, one that writes a web shell to disk and one that runs entirely in memory. This gives attackers a complete, public attack path where previously only isolated pieces of the vulnerability were known. There are currently no confirmed reports of this exploit being used in real attacks.

Importantly, exploitation only works under specific conditions: the application must use the RadAsyncUpload control with a server-side handler reading upload results, and it must be configured with an explicit, non-default encryption key, ironically a setting Telerik itself recommends as a hardening measure. Versions from 2010.1.309 through 2026.2.519 are affected, with 2026.2.708 and later fixed.

Key Takeaway: Australian businesses using Telerik UI for ASP.NET AJAX should update to version 2026.2.708 or later immediately and review whether their RadAsyncUpload configuration matches the vulnerable setup described by researchers.

Telerik RCE patch management web application security vulnerability

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.