type: cve ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [cve, telerik, padding-oracle, rce, framework] ยท confidence: medium ยท severity: high ยท affected_sectors: [technology] ยท au_impact: true
CVE-2026-13181
CVE-2026-13181 (CVSS 8.1) is an AES-CBC 'padding oracle' flaw in Telerik UI for ASP.NET AJAX. A public exploit chain (dubbed TantoSec) turns the padding oracle into unauthenticated remote code execution for applications running a specific non-default configuration.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-13181 (CVSS 8.1) |
| Type | AES-CBC padding oracle โ unauthenticated RCE |
| Patched | July 2026 by Progress |
| Exploitation | No confirmed in-the-wild exploitation |
| Source | The Hacker News โ Tier 2/4 |
The public chain means organisations running Telerik UI in the affected configuration should prioritise patching despite the absence of confirmed attacks.