Threat reportVulnerabilityTL-2026-2369

Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE (CVE-2026-13181–13184)

highACTIVE

Telerik UI for ASP.NET AJAX (TL-2026-2369), also tracked as Telerik RAU Padding Oracle Chain, is a high-severity software vulnerability scored CVSS 8.1, first published 2026-09-07. It has no confirmed attribution, affects Progress Software Telerik UI for ASP.NET AJAX, references 4 CVEs (CVE-2026-13181, CVE-2026-13182, CVE-2026-13183), maps to 9 MITRE ATT&CK techniques (T1021, T1027, T1036), and is covered by 9 detection rules and 7 indicators of compromise.

CVSS
8.1/10High
CVEs
4Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-2369

Threat ID
TL-2026-2369
Also known as
Telerik RAU Padding Oracle Chain, Telerik RCE Chain July 2026
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, information-technology, automotive, manufacturing
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
7

Malware and tooling in Telerik UI for ASP.NET AJAX

Malware and tooling: Mailto

How Telerik UI for ASP.NET AJAX works

Progress Telerik UI for ASP.NET AJAX versions 2010.1.309 through 2026.2.519 contain a chain of four vulnerabilities in the RadAsyncUpload control that together enable unauthenticated remote code execution. An AES-CBC padding oracle (CVE-2026-13182/13183) allows attackers to forge encrypted upload configuration, which is then used to trigger an unguarded type-resolution flaw (CVE-2026-13181, CVSS 8.1) and load a mixed-mode DLL via the AssemblyInstaller deserialization gadget. A public PoC exploit (telerik-rau-exploit) and two mixed-mode DLL payloads (webshell-to-disk and in-memory) were published by TantoSec on September 7, 2026. The vendor fixed the chain in version 2026.2.708 (July 8, 2026) by migrating from AES-CBC to AES-GCM authenticated encryption. No confirmed exploitation in the wild as of the disclosure date, but the historical precedent of CVE-2019-18935 — the same component, same gadget chain — being heavily exploited by ransomware crews and nation-state actors makes this a high-priority target for defenders.

## Overview

Progress Telerik UI for ASP.NET AJAX is a widely deployed enterprise UI component library, used by at least 14,740 verified companies across finance, IT services, government, and automotive sectors. The RadAsyncUpload control, which provides drag-and-drop file upload functionality, contains a chain of cryptographic and deserialization weaknesses that allow an unauthenticated remote attacker to achieve arbitrary code execution with IIS application pool privileges.

## The Vulnerability Chain

### CVE-2026-13182 — AES-CBC Padding Oracle (CVSS 7.5)

The RadAsyncUpload control encrypts client-side state using AES-CBC with no integrity check (HMAC). When the server decrypts a tampered ciphertext, two distinct error conditions occur: a CryptographicException on bad padding versus an InvalidOperationException on valid padding but invalid JSON. This differential — a "decrypt-versus-parse" oracle — allows an attacker to probe ciphertext bytes and recover the plaintext without knowing the encryption key. The oracle is exposed through two entry points: the async upload handler path (AsyncUploadHandler.GetConfiguration, which decrypts the _serializedConfiguration hidden field and passes it to JavaScriptSerializer.Deserialize) and the postback path (PlayClientState → AsyncUploadClientStateConverter, which decrypts per-file metaData blobs). The 2026.1.421 partial patch only wrapped the handler path in a unified try/catch, leaving the postback path unpatched and the oracle fully operational.

### CVE-2026-13183 — Timing-Based Oracle Variant (CVSS 7.5)

Discovered by Justin Steven of TantoSec, this variant exploits measurable timing differences between the two code paths: bad padding fails early, while good-padding-but-bad-JSON takes measurably longer. Even when customErrors is set to On or RemoteOnly to suppress distinguishable error responses, the timing differential persists. The attack uses the "Timeless Timing Attacks" technique (Van Goethem et al., USENIX Security 2020), racing two requests against each other in the same TCP packet so that the order of responses carries the timing signal independent of network latency. Demonstrated consistently across approximately 221ms RTT from Melbourne to us-east-1.

### CVE-2026-13184 — Predictable Default HMAC Key (CVSS 7.5)

When Telerik.Upload.ConfigurationHashKey is not explicitly set in web.config and machineKey is left at its default AutoGenerate setting, the upload metadata integrity protection falls back to a predictable default key. This enables attackers to forge protected upload metadata, including the TempTargetFolder path used in later exploit stages.

### CVE-2026-13181 — Unguarded Type Resolution / Deserialization RCE (CVSS 8.1)

The FileUploaded event handler's UploadResult property calls Type.GetType(obj.FileType) using the attacker-controlled AsyncUploadTypeName value without any allowlist or base-type constraint. The resolved type is then deserialized via JavaScriptSerializer with property values from the attacker-controlled SerializedData. The chosen gadget is System.Configuration.Install.AssemblyInstaller, whose Path setter calls Assembly.LoadFrom(path), loading an attacker-supplied mixed-mode DLL.

## The Sacrificial Block Technique

Because the AES-CBC IV is statically derived from Rfc2898DeriveBytes(password, SALT) and never sent with the ciphertext, the first plaintext block cannot be directly controlled. The exploit uses a "sacrificial block" technique: it decrypts the _serializedConfiguration from right to left via the oracle until a block boundary falls inside the AllowedFileExtensions key name. Everything left of the cut is reused verbatim (carrying TargetFolder, TempTargetFolder, MaxFileSize, TimeToLive, CsrfToken, and the start of AllowedFileExtensions). The first block after the cut is a sacrificial block whose garbage plaintext falls inside the JSON string key value (e.g., AllowedFileq9%Kf2#z). The remaining blocks are forged with backwards-CBC: closing the junk key with a throwaway value, then appending ",AllowedFileExtensions":["dll"]}. JavaScriptSerializer honors the last occurrence of duplicate keys, so only the forged .dll extension survives. If the sacrificial block produces breaking bytes (quote, backslash, control character), another sacrificial block is added to reshuffle the garbage.

## The Mixed-Mode DLL Payloads

The DLL is a C++/CLI "It Just Works" (IJW) mixed-mode assembly — simultaneously a valid managed .NET assembly and a native Windows PE. When Assembly.LoadFrom is called, the Windows loader fires DllMain(DLL_PROCESS_ATTACH) before any managed code executes. The CLR caches assemblies by manifest name, so DllMain only fires once per name per process; the exploit patches the .NET manifest name in the DLL bytes before each upload to bypass this cache.

Two payloads are provided: (1) a write-webshell that reads the IIS config path from GetCommandLineW(), parses the physicalPath (web root), and writes a self-decrypting .aspx file (key derived from filename, encrypted on disk) that survives app pool recycles, and (2) an in-memory webshell that hooks into the request pipeline and responds to any URL when a secret HTTP header is present, running the header value through cmd.exe. The in-memory variant leaves no disk artifact but dies on app pool recycle.

## Exploit Tooling

The telerik-rau-exploit tool (Go, published on GitHub) runs as a pipeline of numbered phases totaling approximately 127,000 oracle queries. At roughly 30 requests per second, the full chain completes in just over one hour against a lab target. The phases are: (1) decrypt _serializedConfiguration to find the AllowedFileExtensions cut point (~5,200 requests), (2) decrypt again to locate the TempTargetFolder blob (~49,500 requests), (4) forge the AllowedFileExtensions suffix with backwards-CBC (~62,800 requests), (5) assemble the forged token, (6) refresh session and swap prefix for live CsrfToken/PageGUID, (7) recover the CryptoService IV via the MetaData oracle and decrypt TempTargetFolder (~74,400 requests), (8) forge the MetaData blob with the AssemblyInstaller gadget (~127,000 requests), and (9) POST the forged rau_ClientState to trigger Assembly.LoadFrom and DllMain.

## Affected Versions

All versions of RadAsyncUpload from 2010.1.309 through 2026.2.519 (2026 Q2) are affected. The fix was shipped in version 2026.2.708 (2026 Q2 SP1), released July 8, 2026. Additional related components (RadPersistenceManager, RadDockLayout) have overlapping affected ranges starting at 2013.1.220. The 2026.2.708 patch replaces AES-CBC with AES-GCM authenticated encryption, which provides an integrity tag on every ciphertext, has no padding to probe, and eliminates the decrypt-versus-parse timing split.

## Exploitation Preconditions

TantoSec states the chain has preconditions not met by a default installation: (1) a page must render RadAsyncUpload whose server-side FileUploaded handler reads the UploadResult, and (2) the application must have an explicit, non-default Telerik.AsyncUpload.ConfigurationEncryptionKey configured — a setting that Telerik has historically recommended as a hardening measure. Without both conditions, affected sites are not exploitable through this specific chain.

## Historical Context

This is not the first critical vulnerability in the RadAsyncUpload component. CVE-2019-18935, a .NET deserialization flaw in the same handler, was exploited in the wild by Netwalker ransomware operators (2020–2021), Blue Mockingbird cryptomining operations (2020 onward), the XE Group cybercrime syndicate (August 2021 onward), and unnamed APT groups (August 2022 onward). CISA added CVE-2019-18935 to its Known Exploited Vulnerabilities catalog in November 2021, and the NSA listed it as one of the most commonly exploited vulnerabilities by Chinese state-sponsored hackers. A joint CISA/FBI/MS-ISAC alert (January 2023) confirmed a US federal agency breach where both an APT and XE Group had exploited the same vulnerable IIS server. Shadowserver honeypot data shows continued exploitation attempts on CVE-2019-18935 through August 2026 — nearly seven years after disclosure. The historical pattern strongly suggests that adversaries will weaponize this new chain once the public PoC is integrated into their toolkits.

## Detection and Defense

Exploitation leaves no obvious trace in standard ASP.NET error logs. Behavioral indicators include: w3wp.exe spawning cmd.exe, new or unexpected .aspx files in the web root, and mixed-mode DLLs (native PE plus .NET manifest) in the RadAsyncUpload temporary folder or App_Data. The in-memory webshell variant leaves no disk artifact but dies on app pool recycle; repeated exploitation attempts become the detection signal. Recommended mitigations if upgrading is not immediately possible: set customErrors to On or RemoteOnly, remove explicit encryption keys from web.config to fall back on MachineKey.Unprotect with AES+HMAC, generate strong non-autogenerated machine keys in IIS with HMACSHA256 validation, and disable the async upload handler entirely via Telerik.Web.DisableAsyncUploadHandler=true if RadAsyncUpload is not needed.

MITRE ATT&CK techniques used in TL-2026-2369

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1218 System Binary Proxy Execution

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505 Server Software Component

Affected products and versions in Telerik UI for ASP.NET AJAX

  • Progress Software — Telerik UI for ASP.NET AJAX
    Vulnerable versions: 2010.1.309 through 2026.2.519
    Fixed in: 2026.2.708 (2026 Q2 SP1)
  • Progress Software — Telerik UI for ASP.NET AJAX — RadAsyncUpload
    Vulnerable versions: 2010.1.309 through 2026.2.519
    Fixed in: 2026.2.708 (2026 Q2 SP1)
  • Progress Software — Telerik UI for ASP.NET AJAX — RadPersistenceManager
    Vulnerable versions: 2013.1.220 through 2026.2.519
    Fixed in: 2026.2.708 (2026 Q2 SP1)
  • Progress Software — Telerik UI for ASP.NET AJAX — RadDockLayout
    Vulnerable versions: 2013.1.220 through 2026.2.519
    Fixed in: 2026.2.708 (2026 Q2 SP1)

Remediation for Telerik UI for ASP.NET AJAX

Patches

  • Apply Telerik UI for ASP.NET AJAX 2026.2.708 (2026 Q2 SP1) — ships July 8, 2026

Immediate actions

  • Upgrade Telerik UI for ASP.NET AJAX to version 2026.2.708 (2026 Q2 SP1) or later — replaces AES-CBC with AES-GCM authenticated encryption
  • If RadAsyncUpload is not needed, disable the handler: <add key="Telerik.Web.DisableAsyncUploadHandler" value="true" /> in web.config

Workarounds

  • Set customErrors to On or RemoteOnly in web.config to suppress error differentials (forces timing-based oracle variant)
  • Remove explicit Telerik.AsyncUpload.ConfigurationEncryptionKey, Telerik.Upload.ConfigurationHashKey, and Telerik.Web.UI.DialogParametersEncryptionKey from web.config to fall back on MachineKey.Unprotect with AES+HMAC
  • Generate strong, non-autogenerated machine keys in IIS with HMACSHA256 validation method
  • Move RadAsyncUpload temporary folder outside App_Data via Telerik.AsyncUpload.TemporaryFolder setting
  • For PersistenceFramework: avoid CookieStateStorageProvider and never derive StorageProviderKey from user input

Longer-term hardening

  • Monitor for new/unexpected .aspx files in web root and mixed-mode DLLs in App_Data or upload temp folders
  • Alert on w3wp.exe spawning cmd.exe as a behavioral indicator of post-exploitation activity
  • Restrict app pool write access to web root as defense-in-depth against webshell deployment
  • Migrate legacy ASP.NET Web Forms applications to modern frameworks to reduce attack surface
  • Maintain a software inventory of Telerik component versions across all IIS servers

CVEs associated with Telerik UI for ASP.NET AJAX

CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184

Weaknesses (CWE) in Telerik UI for ASP.NET AJAX

CWE-470, CWE-502, CWE-209, CWE-208, CWE-321, CWE-326

Timeline of Telerik UI for ASP.NET AJAX

  • Marcio Almeida (TantoSec) reports the padding oracle and deserialization chain to Progress Software via responsible disclosure.
  • Progress Software acknowledges the vulnerability report.
  • TantoSec reports two additional findings to Progress Software.
  • CVEs reserved for the vulnerability chain.
  • TantoSec receives a preview patch from Progress Software for validation.
  • TantoSec returns patch review; additional XXE vulnerability in RadLayoutBuilder flagged.
  • Progress Software ships version 2026.2.708 (2026 Q2 SP1) fixing 13 CVEs across RadAsyncUpload, RadPersistenceManager, RadDockLayout, and other components. AES-CBC replaced with AES-GCM.
  • CVEs and KB articles publicly published. Critical Security Bulletin released by Telerik.
  • BSides Canberra 2026 announces late-addition talk by Marcio Almeida: 'From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET'.
  • TantoSec publishes full technical writeup on tantosec.com and releases telerik-rau-exploit (Go CLI tool) with two mixed-mode DLL payloads (disk-based webshell and in-memory webshell). The Hacker News, UnderCode News, and IT Security News cover the disclosure.

Sources cited for Telerik UI for ASP.NET AJAX

Detection coverage for TL-2026-2369

As of 2026-09-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2369 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats