CVE Tools

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

The Hacker NewsBy The Hacker News

PoC publicTelerik UI for ASP.NET AJAX

Our summary

Security researchers at TantoSec have published a proof-of-concept exploit that enables unauthenticated remote code execution in Telerik UI for ASP.NET AJAX by chaining a padding oracle vulnerability with unsafe deserialization. This attack targets the RadAsyncUpload control in versions 2010.1.309 through 2026.2.519, specifically leveraging CVE-2026-13181 (CVSS 8.1), CVE-2026-13182, and CVE-2026-13183 to bypass encryption protections and load malicious payloads. Although Progress Software patched the issues in version 2026.2.708 released on July 8, the recent release of ready-to-run tooling lowers the barrier for attackers who meet specific non-default configuration requirements.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store