importantSYS.SOURCE: The Hacker News• 2026-09-07T16:50:14+05:30
Telerik UI Padding-Oracle Vulnerability Exploited for Unauthenticated Remote Code Execution
A public exploit has been released for a padding-oracle vulnerability in Telerik UI for ASP.NET AJAX, enabling unauthenticated remote code execution under specific non-default configurations. The vulnerability was patched by Progress in July 2026, but the exploit's release highlights ongoing risks for affected systems.
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.
Security firm TantoSec has published a working exploit chain targeting vulnerabilities
*** END OF TRANSMISSION ***