Home / Sep 08, 2026 / Story
0
#10 The Hacker News general September 07, 2026 at 11:20 UTC

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

By [email protected] (The Hacker News)

AI Summary

TantoSec released a working public exploit chain that leverages an AES-CBC padding oracle vulnerability in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution, though only against applications in a specific non-default configuration. Progress patched the vulnerability chain in July 2026, but the public PoC release substantially raises exploitation risk for organizations that have not yet applied the patch.

Relevance score: 78.0/100

# More from September 08