Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: telerik (1 article)Clear

Public exploit chains a Telerik padding-oracle flaw into unauthenticated code execution

Tanto Security released a working exploit for flaws in Telerik UI for ASP.NET AJAX, a widely used web component set, that chains into unauthenticated remote code execution. The core issue is an AES-CBC padding oracle in the file-upload component: because the encryption does not authenticate the ciphertext, an attacker can tweak encrypted input and read the server's error responses to decrypt protected configuration one byte at a time without the key. That unlocks a .NET deserialization flaw that loads an attacker-supplied assembly and drops a web shell. Progress patched the flaws in July, but the published tool now puts a full attack path in public hands, though only non-default configurations are affected.

Check
Update Telerik UI for ASP.NET AJAX to the patched release, and review applications for the non-default upload configuration this attack requires, prioritizing internet-facing sites now that a working exploit is public.
Affected
Web applications using vulnerable Telerik UI for ASP.NET AJAX in a specific non-default upload configuration (CVE-2026-13181 and related); an unauthenticated attacker can chain the padding oracle and deserialization into remote code execution.
Fix
Patch to the fixed Telerik version, avoid the vulnerable upload configuration, add web application firewall rules for the exploit's request patterns, monitor for web shells and unexpected assembly loads, and rotate keys.