HackerFeeds

CyberSecurity News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

The Hacker News
· September 7, 2026

AI summary

A vulnerability in Telerik UI for ASP.NET AJAX has been exploited to achieve unauthenticated remote code execution through a padding oracle bug. The exploit, demonstrated by TantoSec, relies on a specific non-default application configuration. Progress issued a patch for the vulnerability in July. There have been no confirmed instances of this exploit being used in the wild. The publication of a working exploit chain by TantoSec raises awareness of the potential risk. The vulnerability is related to an AES-CBC padding oracle issue in Telerik UI.

Read the full article at The Hacker Newsthehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.