DIRAS TAKE
Urgent — public exploit code exists, so prioritize remediation for internet-facing Telerik UI for ASP.NET AJAX instances and apply the vendor fix immediately.
What is CVE-2026-13181?
An unauthenticated attacker who can reach Telerik UI for ASP.NET AJAX over the network can run arbitrary code on vulnerable servers. CVE-2026-13181 allows crafted upload metadata to influence AsyncUploadTypeName processing and force unsafe, attacker-controlled type resolution leading to remote code execution. Affected releases are 2010.1.309 through versions before 2026.2.708; exploitation requires only network access to the vulnerable component and no valid account or user interaction.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Progress Software Telerik UI for ASP.NET AJAX are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2026.x | 2010.1.309 – before 2026.2.708 | 2026.2.708 |
Is CVE-2026-13181 being exploited?
Public exploit code is available.
How to fix CVE-2026-13181
- Upgrade Telerik UI for ASP.NET AJAX to 2026.2.708
- If you cannot upgrade immediately, block or restrict access to AsyncUpload endpoints from untrusted networks
- Monitor upload-related logs and alerts for anomalous or forged metadata and unusual type-resolution activity
- Follow vendor guidance for any additional configuration hardening or temporary mitigations
Frequently asked questions
Is CVE-2026-13181 being actively exploited?
Public exploit code is available for CVE-2026-13181, indicating a higher risk of active exploitation.
Which Telerik UI for ASP.NET AJAX versions are affected by CVE-2026-13181?
Telerik UI for ASP.NET AJAX versions from 2010.1.309 up to but not including 2026.2.708 are affected.
Is there a patch for CVE-2026-13181?
Yes. Progress fixed the issue in Telerik UI for ASP.NET AJAX version 2026.2.708.
Does CVE-2026-13181 require authentication?
No. The vulnerability can be exploited without valid credentials against exposed Telerik UI for ASP.NET AJAX endpoints.
References
- nvd.nist.gov/vuln/detail/CVE-2026-13181
- cve.org/CVERecord?id=CVE-2026-13181
- telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-rau-asyncuploadtypename-deserialization-CVE-2026-13181
- All Progress Software CVEs on CVE Radar
- CVEs published in September 2026