Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
VulnerabilitiesCyberDeltaForce Newsroom

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released. The vulnerability puts affected the affected technology systems at risk when the vulnerable service or function is reachable from attacker-controlled network traffic.

The Hacker NewsSep 7, 2026, 11:20 AM UTC3 min read
IN 30 SECONDS

Understand the story quickly

What happenedSource reporting

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released.

Who or what is affectedSource reporting

The vulnerability puts affected the affected technology systems at risk when the vulnerable service or function is reachable from attacker-controlled network traffic.

Why it mattersSource reporting

Confirmed Security outcome — successful exploitation can execute attacker-controlled code in the affected application or service.

Defender next stepCDF guidance

Inventory affected products and versions.

THE NEWS

The full story

Source-grounded reporting, presented as a continuous narrative.

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released. The vulnerability puts affected the affected technology systems at risk when the vulnerable service or function is reachable from attacker-controlled network traffic. Exposure — Required condition: an affected the affected technology instance is reachable from a network position available to the attacker.

Confirmed Security outcome — successful exploitation can execute attacker-controlled code in the affected application or service. There are no confirmed reports of exploitation in the wild. A security weakness in the affected technology is being tracked as a newly reported vulnerability.

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP. The available description indicates that the vulnerable path can be reached remotely or from an untrusted network, so the exposure of the affected technology becomes part of the attack condition. The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls.

The practical reach depends on the privileges and resources available to that process. The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries.

Security firm TantoSec has published a working exploit chain targeting vulnerabilities. Confirmed Initial trigger — attacker-controlled network input reaches the vulnerable function on the affected the affected technology service. Exploit mechanism — Not publicly disclosed in enough technical detail to describe the mechanism without inference.

The reported consequence is code execution, meaning successful exploitation could make the affected application or process run attacker-controlled code. NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. The Hacker News published the primary report used for this article on Sep 7, 2026.

Defender interruption point — Identify remotely reachable the affected technology; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity. Inventory affected products and versions. Validate external and internal reachability of the vulnerable function.

Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.

SOURCE EVIDENCE

What the reporting is based on

The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

Open source
CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

CDF ANALYSIS

What this means

The story is primarily about a software weakness. Risk depends on whether the affected product and versions are present, whether the vulnerable function is reachable, whether exploitation is public or active, and what privileges the affected process carries.

TECHNICAL PATH

Attack & Exploitation Path

A practical view of the conditions, trigger, technical path, and potential security outcome described by the available evidence.

  1. 1

    Exposure — Required condition: an affected the affected technology instance is reachable from a network position available to the attacker.

  2. 2

    Confirmed Initial trigger — attacker-controlled network input reaches the vulnerable function on the affected the affected technology service.

  3. 3

    Exploit mechanism — Not publicly disclosed in enough technical detail to describe the mechanism without inference.

  4. 4

    Confirmed Security outcome — successful exploitation can execute attacker-controlled code in the affected application or service. The practical reach depends on the privileges and resources available to that process.

  5. 5

    Defender interruption point — Identify remotely reachable the affected technology; remove unnecessary exposure; apply the vendor fix or mitigation; then review service, network and identity telemetry for exploitation attempts or unexpected follow-on activity.

DEFENDER ACTIONS

What security teams should check now

  • Inventory affected products and versions.
  • Validate external and internal reachability of the vulnerable function.
  • Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
OPEN QUESTIONS

What is not yet confirmed

  • Available reporting does not currently indicate exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards