Telerik UI Vulnerability Chain Enables Unauthenticated RCE Attacks

Telerik UI Vulnerability Chain Enables Unauthenticated RCE Attacks

First seen 7 Sep 2026, 11:51 UTC GbhackersCybersecuritynewsThehackernewstantosec.combishopfox.com+1 57.8

Article Content

Browse articles
ThreatCluster

A significant vulnerability chain in Telerik UI for ASP.NET AJAX has been disclosed, allowing unauthenticated attackers to achieve remote code execution (RCE) through a padding oracle exploit. The vulnerabilities affect versions 2010.1.309 to 2026.2.519, with a patch available in version 2026.2.708. The attack exploits a combination of an unauthenticated AES-CBC padding oracle and insecure deserialization in the RadAsyncUpload component. Researchers from Tanto Security demonstrated the exploit, releasing a proof-of-concept tool that includes payloads for executing commands on vulnerable servers. Progress Software has confirmed the vulnerabilities and released advisories, but there are no known instances of exploitation in the wild as of now. Users are urged to upgrade to the patched version to mitigate the risks. The vulnerabilities are tracked under CVEs including CVE-2026-13181 and CVE-2026-13182.

Key Points: • Telerik UI for ASP.NET AJAX versions 2010.1.309 to 2026.2.519 are vulnerable. • Exploitation requires specific non-default configurations to be effective. • A proof-of-concept tool has been released, but no active exploitation has been confirmed.

Ask AI about this cluster

Timeline

2014-12-25
CVE-2014-2217 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2017-08-23
CVE-2017-11317 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2019-12-11
CVE-2019-18935 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-13181, 13182 published
Progress Software published advisories for multiple vulnerabilities in Telerik UI, including RCE risks.
tantosec.com
2026-07-22
CVE-2026-13183 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-13184 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-13185 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-22
CVE-2026-13182 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-07
TantoSec discloses exploit details
TantoSec released a proof-of-concept exploit for a padding oracle vulnerability in Telerik UI, enabling unauthenticated RCE.
Thehackernews
2026-09-07
Progress Software issues patch
Progress Software advised users to upgrade to version 2026.2.708 to mitigate the vulnerabilities.
Cybersecuritynews