High

Telerik, ASP.NET AJAX, CVE-2026-13181, Remote Code Execution, Public Exploit, Progress Software

Telerik UI CVE-2026-13181: Unauth RCE, Public Exploit

Telerik UI CVE-2026-13181 is a CVSS 8.1 type-resolution flaw now chained into unauthenticated RCE by a public exploit. It hits non-default configs; patch to 2026.2.708.

Telerik UI CVE-2026-13181 is a CVSS 8.1 unsafe type-resolution flaw in Telerik UI for ASP.NET AJAX that a newly released public exploit chains into unauthenticated remote code execution, though only against applications in a specific non-default configuration. Security firm TantoSec published a working exploit chain on September 7, 2026, pairing a detailed write-up with a ready-to-run command-line tool, telerik-rau-exploit, and two payloads: one that writes a web shell to disk and one that runs entirely in memory. Progress Software had already patched the flaws in July, but the tooling now puts a complete attack path in public hands for the first time.

The chain abuses an AES-CBC padding oracle in the RadAsyncUpload file-upload control, and CVE-2026-13181 is the most serious of the set, tracked alongside CVE-2026-13182 through CVE-2026-13185. Progress shipped the fix in version 2026.2.708 (2026 Q2 SP1) on July 8 and published the advisory on July 22. The affected range is RadAsyncUpload in versions 2010.1.309 through 2026.2.519; 2026.2.708 and later are fixed. The bug echoes the widely exploited 2019 Telerik flaw CVE-2019-18935.

There are no confirmed reports of exploitation in the wild yet. The CVSS "high" attack-complexity rating reflects the configuration prerequisites, not any difficulty once they are met. TantoSec is explicit that running an affected version is not enough: exploitation requires both a page that renders a RadAsyncUpload control whose handler reads the upload result, and an explicit, non-default encryption key configured for the control, which, in a twist, is a hardening setting Telerik itself recommends.

Is my Telerik application actually exploitable?

Only if two non-default conditions are both true. First, the application must render a RadAsyncUpload control whose server-side handler reads the upload result. Second, it must be configured with an explicit, custom encryption key for that control rather than the default. Sites on an affected version that lack either condition are not exploitable through this chain, so the practical exposure is narrower than the raw version range suggests, but administrators should confirm their configuration rather than assume.

Why does a public exploit change the risk overnight?

Because it removes the research barrier. The flaws were patched in July and quietly tracked, but until September 7 there was no public method or tool. A released proof-of-concept with a command-line runner and drop-to-disk plus in-memory payloads means any attacker can now attempt the chain without developing it themselves. When a patch has existed for two months and a working exploit lands, the window belongs to defenders who already patched, and closes fast for those who did not.

Detail

Value

CVE

CVE-2026-13181 (chain: 13182-13185)

CVSS 3.1

8.1 High (CWE-470 unsafe type resolution)

Product

Telerik UI for ASP.NET AJAX, RadAsyncUpload

Affected

2010.1.309 through 2026.2.519

Fixed

2026.2.708 (Q2 2026 SP1), July 8

Exploit

Public tool telerik-rau-exploit, Sept 7; no ITW yet

Our read

This is a clean example of why "patched in July" is not the same as "safe in September." The vulnerability sat with a fix available and low attention until a public exploit turned it into a point-and-click attack. The configuration precondition is real and narrows exposure, but it depends on a hardening setting Telerik recommends, so plenty of well-run sites will meet it. The defensible move is to patch to 2026.2.708 now, and to verify whether your own applications actually meet the exploitable conditions rather than guessing from the version number. Knowing your real exposure beats trusting the base score.

Reporting by The Hacker News; exploit detail per TantoSec; version and CVSS data per Progress and NVD. Sources linked above.

Related: What is a web shell? and What is a zero-day?.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.