hacker-news · Crawled Sep 7, 2026
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
2 IoCs
Read original article ↗
AI Summary
A public proof-of-concept exploit has been released that chains multiple vulnerabilities in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution. The attack chain leverages a padding oracle (CVE-2026-13182) to decrypt and forge encrypted state, leading to type confusion and deserialization of a malicious mixed-mode DLL via an unguarded type resolution flaw (CVE-2026-13181). Successful exploitation requires non-default configurations, including use of a custom encryption key and presence of the RadAsyncUpload control. While no confirmed in-the-wild exploitation has been reported, the release of working tooling increases risk for misconfigured systems.
AI-extracted · verify before operational use