#10
The Hacker News
general
September 07, 2026 at 11:20 UTC
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
By [email protected] (The Hacker News)
AI Summary
TantoSec released a working public exploit chain that leverages an AES-CBC padding oracle vulnerability in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution, though only against applications in a specific non-default configuration. Progress patched the vulnerability chain in July 2026, but the public PoC release substantially raises exploitation risk for organizations that have not yet applied the patch.
Relevance score: 78.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →