• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-13181: pre-auth remote code execution in Progress Software Telerik UI for ASP.NET AJAX

An unauthenticated attacker who can reach Telerik UI for ASP.NET AJAX over the network can run arbitrary code on vulnerable servers. CVE-2026-13181 allows crafted upload metadata to influence AsyncUploadTypeName processing and force unsafe, attacker-controlled type resolution leading to remote code execution. Affected releases are 2010.1.309 through versions before 2026.2.708; exploitation requires only network access to the vulnerable component and no valid account or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.1HIGH
EPSS
0.00676
CWE
CWE-470
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — public exploit code exists, so prioritize remediation for internet-facing Telerik UI for ASP.NET AJAX instances and apply the vendor fix immediately.

What is CVE-2026-13181?

An unauthenticated attacker who can reach Telerik UI for ASP.NET AJAX over the network can run arbitrary code on vulnerable servers. CVE-2026-13181 allows crafted upload metadata to influence AsyncUploadTypeName processing and force unsafe, attacker-controlled type resolution leading to remote code execution. Affected releases are 2010.1.309 through versions before 2026.2.708; exploitation requires only network access to the vulnerable component and no valid account or user interaction.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Progress Software Telerik UI for ASP.NET AJAX are affected?

BRANCHAFFECTEDFIXED
2026.x2010.1.309 – before 2026.2.7082026.2.708

Is CVE-2026-13181 being exploited?

Public exploit code is available.

How to fix CVE-2026-13181

  1. Upgrade Telerik UI for ASP.NET AJAX to 2026.2.708
  2. If you cannot upgrade immediately, block or restrict access to AsyncUpload endpoints from untrusted networks
  3. Monitor upload-related logs and alerts for anomalous or forged metadata and unusual type-resolution activity
  4. Follow vendor guidance for any additional configuration hardening or temporary mitigations

Frequently asked questions

Is CVE-2026-13181 being actively exploited?

Public exploit code is available for CVE-2026-13181, indicating a higher risk of active exploitation.

Which Telerik UI for ASP.NET AJAX versions are affected by CVE-2026-13181?

Telerik UI for ASP.NET AJAX versions from 2010.1.309 up to but not including 2026.2.708 are affected.

Is there a patch for CVE-2026-13181?

Yes. Progress fixed the issue in Telerik UI for ASP.NET AJAX version 2026.2.708.

Does CVE-2026-13181 require authentication?

No. The vulnerability can be exploited without valid credentials against exposed Telerik UI for ASP.NET AJAX endpoints.

References