Thehackernews
Telerik UI Vulnerability Chain Enables Unauthenticated RCE Attacks
Article Content
A significant vulnerability chain in Telerik UI for ASP.NET AJAX has been disclosed, allowing unauthenticated attackers to achieve remote code execution (RCE) through a padding oracle exploit. The vulnerabilities affect versions 2010.1.309 to 2026.2.519, with a patch available in version 2026.2.708. The attack exploits a combination of an unauthenticated AES-CBC padding oracle and insecure deserialization in the RadAsyncUpload component. Researchers from Tanto Security demonstrated the exploit, releasing a proof-of-concept tool that includes payloads for executing commands on vulnerable servers. Progress Software has confirmed the vulnerabilities and released advisories, but there are no known instances of exploitation in the wild as of now. Users are urged to upgrade to the patched version to mitigate the risks. The vulnerabilities are tracked under CVEs including CVE-2026-13181 and CVE-2026-13182.
Key Points: • Telerik UI for ASP.NET AJAX versions 2010.1.309 to 2026.2.519 are vulnerable. • Exploitation requires specific non-default configurations to be effective. • A proof-of-concept tool has been released, but no active exploitation has been confirmed.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.