<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released]]></title><description><![CDATA[<p dir="auto">TantoSec has published a working proof-of-concept that chains an AES-CBC <em>padding oracle</em> flaw in <strong>Telerik UI for <a href="http://ASP.NET" target="_blank" rel="noopener noreferrer nofollow ugc">ASP.NET</a> AJAX</strong> into unauthenticated remote code execution. The exploit targets a specific, non-default configuration, and <strong>Progress</strong> released a patch for the underlying chain back in July. As of now, there are no confirmed reports of in-the-wild exploitation.</p>
<p dir="auto">The attack hinges on a cryptographic weakness in the Telerik UI component's handling of encrypted data. By repeatedly sending crafted requests and observing the server's padding-error responses, an attacker can decrypt sensitive payloads without valid credentials. TantoSec's research demonstrates how this oracle can then be leveraged to forge a malicious request, ultimately achieving code execution on the target server.</p>
<p dir="auto">It is important to note that this exploit does not affect every deployment. The attack only succeeds against applications that are using a configuration which is <em>not</em> the default. Organizations running standard, out-of-the-box settings are not exposed to this specific chain. Administrators should verify their deployment configuration against the guidance provided in the July advisory from <strong>Progress</strong>.</p>
<p dir="auto">Given the severity of potential unauthenticated RCE, immediate action is recommended for affected users:</p>
<ul>
<li>Apply the latest patches released by <strong>Progress</strong> in July if you have not already done so.</li>
<li>Review your Telerik UI for <a href="http://ASP.NET" target="_blank" rel="noopener noreferrer nofollow ugc">ASP.NET</a> AJAX configuration to confirm whether you are running the vulnerable non-default setup.</li>
<li>Monitor for any unsolicited encrypted payloads or anomalous network traffic directed at web servers, as padding-oracle attacks generate distinctive error patterns.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Has your team audited your Telerik UI deployments to confirm whether they fall into that non-default configuration, or are you waiting on the patch cycle to catch up?</p>
]]></description><link>https://xploitlk.com/topic/258/telerik-ui-padding-oracle-bug-chained-to-unauthenticated-rce-public-exploit-released</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:09:59 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/258.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 06:30:35 GMT</pubDate><ttl>60</ttl></channel></rss>