Back to all news
Security

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

The Hacker News·September 7, 2026·1 min read
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

TantoSec published a proof-of-concept turning an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution, but only against a specific non-default configuration. Progress patched the chain in July; no exploitation in the wild has been confirmed.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store