The full story
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released. The vulnerability puts affected the affected technology systems at risk when the vulnerable service or function is reachable from attacker-controlled network traffic. Exposure — Required condition: an affected the affected technology instance is reachable from a network position available to the attacker.
Confirmed Security outcome — successful exploitation can execute attacker-controlled code in the affected application or service. There are no confirmed reports of exploitation in the wild. A security weakness in the affected technology is being tracked as a newly reported vulnerability.
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP. The available description indicates that the vulnerable path can be reached remotely or from an untrusted network, so the exposure of the affected technology becomes part of the attack condition. The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls.
The practical reach depends on the privileges and resources available to that process. The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries.
Security firm TantoSec has published a working exploit chain targeting vulnerabilities. Confirmed Initial trigger — attacker-controlled network input reaches the vulnerable function on the affected the affected technology service. Exploit mechanism — Not publicly disclosed in enough technical detail to describe the mechanism without inference.
The reported consequence is code execution, meaning successful exploitation could make the affected application or process run attacker-controlled code. NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. The Hacker News published the primary report used for this article on Sep 7, 2026.
Defender interruption point — Identify remotely reachable the affected technology; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity. Inventory affected products and versions. Validate external and internal reachability of the vulnerable function.
Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
What the reporting is based on
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities
Open sourceReporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What this means
The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries.
Attack & Exploitation Path
A practical view of the conditions, trigger, technical path, and potential security outcome described by the available evidence.
- 1
Exposure — Required condition: an affected the affected technology instance is reachable from a network position available to the attacker.
- 2
Confirmed Initial trigger — attacker-controlled network input reaches the vulnerable function on the affected the affected technology service.
- 3
Exploit mechanism — Not publicly disclosed in enough technical detail to describe the mechanism without inference.
- 4
Confirmed Security outcome — successful exploitation can execute attacker-controlled code in the affected application or service. The practical reach depends on the privileges and resources available to that process.
- 5
Defender interruption point — Identify remotely reachable the affected technology; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity.
What security teams should check now
- Inventory affected products and versions.
- Validate external and internal reachability of the vulnerable function.
- Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
What is not yet confirmed
- Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.