Skip to content
cve — cve-2026-13181

grep -rl "CVE-2026-13181" ./articles

CVE-2026-13181

TantoSec released a working exploit on 7 September for a padding-oracle chain in Telerik's RadAsyncUpload control that ends in unauthenticated code execution. Its precondition is an explicit, non-default encryption key — the setting administrators were told to configure. Roughly 127,000 requests and an hour in a lab.

1 article — 2026-09-07

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

The Telerik exploit chain needs the hardening step Telerik recommends

2026-09-07Security

TantoSec released a working exploit on 7 September for a padding-oracle chain in Telerik's RadAsyncUpload control that ends in unauthenticated code execution. Its precondition is an explicit, non-default encryption key — the setting administrators were told to configure. Roughly 127,000 requests and an hour in a lab.

../cve — every identifier we have covered