Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
Security researchers at TantoSec have published a proof-of-concept exploit that enables unauthenticated remote code execution in Telerik UI for ASP.NET AJAX by chaining a padding oracle vulnerability with unsafe deserialization. This attack targets the RadAsyncUpload control in versions 2010.1.309 through 2026.2.519, specifically leveraging CVE-2026-13181 (CVSS 8.1), CVE-2026-13182, and CVE-2026-13183 to bypass encryption protections and load malicious payloads. Although Progress Software patched the issues in version 2026.2.708 released on July 8, the recent release of ready-to-run tooling lowers the barrier for attackers who meet specific non-default configuration requirements.