Vulnerability
Published 2026-09-07
Verified 2026-09-19

Telerik UI for ASP.NET AJAX RCE chain (CVE-2026-13181+); public exploit 7 Sep

Progress Telerik critical security bulletin (updated 22 July 2026) covers a chain in UI for ASP.NET AJAX RadAsyncUpload / RadPersistenceManager / RadDockLayout (CVE-2026-13181 through CVE-2026-13186 and CVE-2026-13190). Unauthenticated remote code execution is possible when preconditions are met (reachable RadAsyncUpload with FileUploaded handler reading UploadResult; explicit non-default Telerik.AsyncUpload.ConfigurationEncryptionKey). CVE-2026-13181 is CVSS 3.1 8.1 High (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Fixed in 2026.2.708 (2026 Q2 SP1); affected RadAsyncUpload builds from 2010.1.309 through 2026.2.519. NEW material this window: TantoSec (7 September 2026) published a full write-up and public exploit tooling (telerik-rau-exploit) turning the AES-CBC padding oracle into webshell/in-memory payloads. Progress/Telerik state no confirmed in-the-wild exploitation in the bulletin era; treat the newly public exploit tooling as elevating patch priority. Primary: Telerik KB bulletin; research: TantoSec.

Product
Progress Telerik UI for ASP.NET AJAX
Versions
RadAsyncUpload 2010.1.309–2026.2.519 (and related Persistence/DockLayout ranges per bulletin); fixed in 2026.2.708 (2026 Q2 SP1)+
CVSS
(CVE-2026-13181, CVSS 3.1)
Exploited in Australia?
unknown
Patch to
Upgrade to Telerik UI for ASP.NET AJAX 2026.2.708 (2026 Q2 SP1) or later; if delayed, apply vendor mitigation checklist (customErrors, encryption-key review, cookie persistence settings)

Primary: Telerik / Progress — Critical RCE chain bulletin (Jul 2026; CVEs 13181+) · Vendor: Telerik UI for ASP.NET AJAX (vendor KB) · CVE: CVE-2026-13181, CVE-2026-13186, CVE-2026-13190 · TantoSec — public exploit write-up (7 Sep 2026)

vulnerabilities cloud identity