Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [cve, telerik, padding-oracle, rce, framework] ยท confidence: medium ยท severity: high ยท affected_sectors: [technology] ยท au_impact: true

CVE-2026-13181

CVE-2026-13181 (CVSS 8.1) is an AES-CBC 'padding oracle' flaw in Telerik UI for ASP.NET AJAX. A public exploit chain (dubbed TantoSec) turns the padding oracle into unauthenticated remote code execution for applications running a specific non-default configuration.

Attribute Detail
CVE CVE-2026-13181 (CVSS 8.1)
Type AES-CBC padding oracle โ†’ unauthenticated RCE
Patched July 2026 by Progress
Exploitation No confirmed in-the-wild exploitation
Source The Hacker News โ€” Tier 2/4

The public chain means organisations running Telerik UI in the affected configuration should prioritise patching despite the absence of confirmed attacks.

Source