CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
CVE-2019-18935 Telerik UI Deserialization Exploited to (TL-2026-2726) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-28. It has no confirmed attribution, affects Progress Software Telerik UI for ASP.NET AJAX, references 2 CVEs (CVE-2019-18935, CVE-2017-11317), maps to 16 MITRE ATT&CK techniques (T1027, T1033, T1057), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-2726
- Threat ID
- TL-2026-2726
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- information technology, government administration, finance, unspecified internet-facing organizations
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 30
- Updates
- 2026-09-28 · revalidated 1× · latest source
Malware and tooling in CVE-2019-18935 Telerik UI Deserialization Exploited to
Malware and tooling: Godzilla Webshell, JuicyPotato, xmrig, PrintSpoofer, SweetPotato, Telegram Bot API
AhnLab ASEC documented two ongoing attack cases exploiting the CVE-2019-18935 .NET deserialization vulnerability in Telerik UI for ASP.NET AJAX (RadAsyncUpload component, versions prior to 2020.1.114) on unpatched Windows IIS servers. One campaign installed a memory-resident Godzilla-style web shell and the SweetPotato privilege-escalation tool after gaining w3wp.exe-level code execution; a second campaign deployed a Rust-based WordPress vulnerability scanner for reconnaissance.
How CVE-2019-18935 Telerik UI Deserialization Exploited to works
Progress Telerik UI for ASP.NET AJAX contains a critical .NET deserialization vulnerability (CVE-2019-18935, CVSS 3.1 9.8) in the RadAsyncUpload file-upload handler, present in versions from 2011.1.315 through 2019.3.1023 (fixed default type whitelisting shipped in 2020.1.114 / R1 2020). Exploitation typically chains CVE-2017-11317, which breaks the hard-coded AES key protecting RadAsyncUpload's encrypted `rauPostData` configuration parameter (default value `PrivateKeyForEncryptionOfRadAsyncUploadConfiguration`), letting an attacker forge and decrypt the parameter, upload an arbitrary mixed-mode assembly to a writable path, and then submit a second crafted request that deserializes a `System.Configuration.Install.AssemblyInstaller` gadget pointed at that assembly's `Path` property. When deserialized, the CLR loads the DLL and invokes its `DllMain`, yielding remote code execution in the context of the IIS worker process `w3wp.exe`.
AhnLab's ASEC documented two distinct, ongoing attack cases against unpatched IIS servers exploiting this chain. In the first, the attacker executed a reverse shell that opened a Windows socket back to a remote server at 206.82.6[.]22:80, redirected the socket as stdin/stdout/stderr, and spawned `cmd.exe` for interactive remote command execution. The attacker then queried the host (hostname, user privileges, running processes) before deploying SweetPotato, a local-service-to-SYSTEM privilege-escalation tool that bundles RottenPotato, JuicyPotato, and PrintSpoofer-style Print Spooler RPC abuse: it stands up a fake named pipe, forces the SYSTEM-privileged spooler service to connect to it via `RpcRemoteFindFirstPrinterChangeNotificationEx()`, and impersonates the resulting SYSTEM token via `SeImpersonatePrivilege`/`SeAssignPrimaryTokenPrivilege` to launch an elevated process. With SYSTEM access, the attacker installed a Godzilla-style memory-resident web shell: a DLL (observed as `godmemshell.Dll`) is injected into the Telerik ASP.NET application, where it registers a malicious `VirtualPathProvider` handler that serves a virtual ASPX endpoint existing only in worker-process memory, with no file ever written to disk. The web shell receives AES-encrypted .NET payloads over HTTP, decrypts and JIT-loads them in memory, stores session state in cookies, and re-encrypts responses before returning them, giving the operator persistent, largely fileless command execution, file transfer, and (per public Godzilla tooling) Mimikatz/PetitPotam-class post-exploitation capability.
In the second, separate attack case, the actor used the same CVE-2019-18935 initial-access vector to deploy a purpose-built Rust binary that functions as an internet-wide WordPress reconnaissance scanner. After compromise, the tool retrieves a candidate target list from a remote server (observed fetching `Ins.txt` from 65.98.5[.]158:31337) and asynchronously probes roughly 53 candidate URL paths per host looking for an exposed, unfinished WordPress installation/configuration page (`/wp-admin/setup-config.php` or `/wp-admin/install.php`) that would allow an unauthenticated attacker to complete setup and seize the site. Additional scanner configuration and target lists were retrieved from 2.59.133[.]147:31338 (`ins.txt`, `sm.json`) and 45.138.16[.]187:31337 (`bb.json`, `cofuz.json`). Results — vulnerable URLs and their public IPs — are exfiltrated as a `red.txt` attachment sent via the Telegram Bot API, using Telegram as a low-friction, encrypted-by-default C2/exfiltration channel that blends into normal HTTPS traffic.
CVE-2019-18935 has a long history of in-the-wild abuse: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and notes it has been used in ransomware campaigns; Red Canary's Blue Mockingbird activity cluster (documented May 2020, active since at least December 2019) exploited the same flaw to drop XMRig Monero-mining DLLs via the `Telerik.Web.UI.WebResource.axd` endpoint, persisting via COR_PROFILER COM hijacking, modified Windows services, and scheduled tasks; and CISA/FBI/MS-ISAC's joint advisory AA23-074A (published 2023-03-15) documented exploitation of the same vulnerability against a U.S. federal civilian executive branch IIS server between November 2022 and January 2023 by two separate intrusion sets, including the cybercriminal group XE Group. ASEC's current reporting states that unpatched-Telerik attack cases 'continue to be observed,' and does not attribute the two 2026 cases to a named actor.
MITRE ATT&CK techniques used in TL-2026-2726
Defense Evasion
T1027 Obfuscated Files or Information; T1620 Reflective Code Loading
Discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell
Command and Control
T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography
Privilege Escalation
T1134.001 Token Impersonation/Theft
Initial Access
T1190 Exploit Public-Facing Application
Persistence
Exfiltration
T1567 Exfiltration Over Web Service
Reconnaissance
Affected products and versions in CVE-2019-18935 Telerik UI Deserialization Exploited to
- Progress Software — Telerik UI for ASP.NET AJAX
Vulnerable versions: 2011.1.315 through 2019.3.1023 (RadAsyncUpload prior to default type whitelisting)
Fixed in: 2020.1.114 (R1 2020) and later
Remediation for CVE-2019-18935 Telerik UI Deserialization Exploited to
Patches
- Progress Telerik UI for ASP.NET AJAX R1 2020 (2020.1.114) or later
Immediate actions
- Upgrade Telerik UI for ASP.NET AJAX to version 2020.1.114 (R1 2020) or later, which enables RadAsyncUpload type whitelisting by default
- If immediate upgrade is not possible, explicitly enable RadAsyncUpload type whitelisting per Telerik/Progress security guidance
- Block or closely monitor outbound connections from IIS worker processes (w3wp.exe) to non-business destinations, including the identified C2 IPs 206.82.6.22, 65.98.5.158, 2.59.133.147, and 45.138.16.187
- Hunt for anomalous w3wp.exe child processes (cmd.exe) and unexpected in-memory .NET assembly loads consistent with a memory-resident web shell
Workarounds
- Restrict or disable the RadAsyncUpload handler if patching is not immediately possible
- Restrict access to Telerik.Web.UI.WebResource.axd and related resource handlers at the web server or WAF layer
- Remove default/placeholder WordPress installations that expose /wp-admin/setup-config.php or /wp-admin/install.php to the internet
Longer-term hardening
- Deploy EDR/memory-forensics tooling capable of inspecting IIS worker-process memory for injected .NET assemblies and rogue VirtualPathProvider registrations, since the Godzilla-style shell writes no file to disk
- Apply least-privilege configuration to IIS application pool identities to reduce the impact of Print-Spooler-based token-impersonation privilege escalation (SweetPotato/PrintSpoofer)
- Disable or restrict the Print Spooler service on servers that do not require it to remove the SeImpersonatePrivilege abuse path used by Potato-family tools
- Maintain a vulnerability-management process that also remediates CVE-2017-11317, which is a common prerequisite for defeating RadAsyncUpload's encryption and exploiting CVE-2019-18935
- Segment externally facing WordPress installations from IIS/Telerik hosts and remove exposed setup/install pages to deny reconnaissance value to compromised-host-launched scanners
CVEs associated with CVE-2019-18935 Telerik UI Deserialization Exploited to
Weaknesses (CWE) in CVE-2019-18935 Telerik UI Deserialization Exploited to
CWE-502
Timeline of CVE-2019-18935 Telerik UI Deserialization Exploited to
- CVE-2019-18935 is reserved as an identifier for the Telerik UI RadAsyncUpload .NET deserialization vulnerability.
- Bishop Fox publishes technical details of CVE-2019-18935, the .NET deserialization RCE in Telerik UI for ASP.NET AJAX's RadAsyncUpload handler.
- NVD publishes CVE-2019-18935 with a Critical CVSS 3.1 base score of 9.8, affecting Telerik UI for ASP.NET AJAX through 2019.3.1023.
- Red Canary publishes research on Blue Mockingbird, an activity cluster that had been exploiting CVE-2019-18935 since at least December 2019 to deploy XMRig Monero-mining DLLs via the Telerik.Web.UI.WebResource.axd endpoint.
- The Australian Cyber Security Centre issues Advisory 2020-008 documenting active exploitation of Telerik UI vulnerabilities, including CVE-2019-18935, against government and commercial targets.
- CISA adds CVE-2019-18935 to the Known Exploited Vulnerabilities Catalog, noting it has been used in ransomware campaigns.
- Per CISA AA23-074A, a threat actor (TA1) begins reconnaissance against a U.S. federal civilian executive branch IIS server later found exploited via CVE-2019-18935, using C2 infrastructure at 137.184.130.162 and 45.77.212.12.
- CISA identifies the start of a window (through early January 2023) in which indicators of compromise tied to CVE-2019-18935 exploitation appear at a federal civilian executive branch agency, involving a second actor identified as the group XE Group.
- CISA, the FBI, and MS-ISAC jointly publish advisory AA23-074A and analysis report AR23-074A detailing exploitation of CVE-2019-18935 against a U.S. government IIS server.
- In the second ASEC-documented case, the attacker exploits CVE-2019-18935 to run a Rust-based WordPress vulnerability scanner that retrieves target lists from 65.98.5.158, 2.59.133.147, and 45.138.16.187, and exfiltrates scan results (red.txt) via the Telegram Bot API.
- In the first ASEC-documented case, the attacker exploits CVE-2019-18935 for a reverse shell to 206.82.6.22:80, performs host discovery, escalates privileges via SweetPotato/PrintSpoofer-style Print Spooler abuse, and installs the memory-resident godmemshell.Dll Godzilla web shell.
- AhnLab ASEC publishes analysis of two ongoing, unattributed attack cases exploiting CVE-2019-18935 against unpatched IIS servers: one installing a Godzilla-style memory web shell and the SweetPotato privilege-escalation tool, the other deploying a Rust-based WordPress vulnerability scanner.
Update history for TL-2026-2726
- 2026-09-28 — Telerik UI CVE-2019-18935 Exploitation: Godzilla Webshell Installation and WordPress Scanner Deployment: What changed No escalation — severity (CRITICAL), exploitability (ACTIVE), and status (ACTIVE) are unchanged. This update is intel enrichment, not a severity/status shift. New indicators (7) 2 Telegram Bot API endpoints exposing the operato
Sources cited for CVE-2019-18935 Telerik UI Deserialization Exploited to
- Vulnerability Attack Case: Installation of a Web Shell and Execution of a Scanner by Exploiting a Telerik UI Vulnerability
- CVE-2019-18935 Detail
- CISA Known Exploited Vulnerabilities Catalog - CVE-2019-18935
- AA23-074A: Threat Actors Exploit Progress Telerik Vulnerability in U.S. Government IIS Server
- MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server
- Blue Mockingbird activity mines Monero cryptocurrency
- CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Progress Telerik UI
- CVE-2019-18935 RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX
- SweetPotato: Local Service to SYSTEM privilege escalation from Windows 7 to Windows 10 / Server 2019
- GodzillaMemoryShellProject.NET
- Distribution of Godzilla WebShell Abusing ViewState (Targeting Financial Sector)
- Telerik UI Remote Code Execution via Insecure Deserialization (CVE-2019-18935)
More in vulnerability
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog
- SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)
Detection coverage for TL-2026-2726
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2726 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.