A four-CVE chain in Telerik UI for ASP.NET AJAX's RadAsyncUpload component can allow unauthenticated remote code execution in affected ASP.NET WebForms applications. CVE-2026-13182 exposes an AES-CBC padding oracle in encrypted client-state handling, enabling recovery and forgery of configuration data; the reported chain also uses decrypt-versus-parse behavior, a predictable HMAC key, and a type-name deserialization gadget. Forged configuration can permit DLL uploads, after which unsafe upload-metadata type resolution in CVE-2026-13181 can load a malicious mixed-mode DLL and execute code in the IIS worker process. The full chain includes CVE-2026-13181 through CVE-2026-13184.
Affected Telerik UI for ASP.NET AJAX releases range from 2010.1.309 through 2026.2.519; Progress Software remediated the issues in version 2026.2.708. Exploitation requires an exposed vulnerable RadAsyncUpload page whose FileUploaded handler reads UploadResult, plus an explicitly configured non-default Telerik.AsyncUpload.ConfigurationEncryptionKey. Organizations should upgrade immediately, review RadAsyncUpload pages and event handlers, and investigate unusual IIS child processes, temporary DLLs, and unexpected ASPX files.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Progress Software publicly documented CVE-2026-13181 through CVE-2026-13184 and its advisory for the Telerik RadAsyncUpload vulnerability chain. The advisory followed the July 8 release of Telerik UI for ASP.NET AJAX 2026.2.708, which patched the issues.
Progress Software addressed CVE-2026-13181 through CVE-2026-13184 in Telerik UI for ASP.NET AJAX version 2026.2.708, released in the 2026 Q2 SP1 update. The affected version range was reported as 2010.1.309 through 2026.2.519.
TantoSec described an attack chain against Telerik UI for ASP.NET AJAX RadAsyncUpload that uses an AES-CBC padding oracle and unsafe type resolution/deserialization to achieve unauthenticated server-side code execution. The reported proof of concept executed a web shell in the IIS worker process; exploitation requires an exposed RadAsyncUpload page whose FileUploaded handler reads UploadResult and a non-default ConfigurationEncryptionKey.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcereddit.com
Open sourcetantosec.com
Open sourcetelerik.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.