News

Public exploit drops for Telerik ASP.NET upload RCE

Progress Telerik's July 2026 critical bulletin patches an unauthenticated RCE chain in UI for ASP.NET AJAX, fixed in 2026.2.708. TantoSec published a public exploit tool on 7 September 2026. The chain needs a non-default ConfigurationEncryptionKey and a page that reads UploadResult.

Public exploit drops for Telerik ASP.NET upload RCE

TantoSec published a full write-up and a public tool on 7 September 2026 that turns an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution. Researcher Marcio Almeida released telerik-rau-exploit the same day. This is not a brand-new zero-day. Progress already shipped the fix in July.

Patched versions are listed in Progress Telerik's Critical Security Bulletin for July 2026. The bulletin covers CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, and CVE-2026-13190. When chained, an unauthenticated remote attacker can run code on the server.

RadAsyncUpload is affected from 2010.1.309 through 2026.2.519. The fixed build is 2026.2.708 (2026 Q2 SP1). RadPersistenceManager and RadDockLayout sit in the same bulletin.

The chain is not a default install. TantoSec says two preconditions have to be true: a reachable page with RadAsyncUpload whose server-side FileUploaded handler reads UploadResult, and an explicit, non-default Telerik.AsyncUpload.ConfigurationEncryptionKey. That key is a recommended hardening setting, and it is also the setting that opens the forge path. If customErrors is On, a timing variant still works (CVE-2026-13183).

One earlier build did not close the story. Version 2026.1.421 silenced the handler oracle and flattened both decrypt failures into one exception, but the postback oracle on rau_ClientState stayed alive through 2026.2.519. Only 2026.2.708 replaces AES-CBC with AES-GCM and ends the chain. TantoSec's lab run used about 127,000 oracle queries at roughly 30 per second, a little over an hour on a local target.

The Hacker News reported no confirmed exploitation in the wild as of 7 September. Progress patched the product on 8 July 2026. The CVEs posted on 22 July. Today's news is the public method and tooling, not an unpatched hole.

Internet-facing upload and management planes keep producing the same class of event, from StyleSmuggler on Magento and Adobe Commerce to N-able's N-central hotfix, a WordPress migration-plugin takeover, and PostgreSQL's logical-decoding RCE.

If any ASP.NET app still ships Telerik UI for AJAX below 2026.2.708 with RadAsyncUpload and a custom ConfigurationEncryptionKey, upgrade now and inventory pages that read UploadResult.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free