Telerik UI Padding-Oracle Bug Enables RCE
A newly discovered exploit in Telerik UI for ASP.NET AJAX allows attackers to perform unauthenticated remote code execution (RCE). Security firm TantoSec has released a proof-of-concept that targets a vulnerability in the AES-CBC "Padding Oracle". This security flaw affects specific configurations that do not conform to the default settings. The vulnerability was patched in July 2026 by Progress, the parent company of Telerik. Despite the release of the exploit, there are currently no confirmed reports of active exploitation in the wild.
However, security researchers warn that the spread of the exploit could be potentially dangerous, especially for companies that have not implemented the recommended security updates. The exploit leverages a combination of two vulnerabilities to gain control over affected systems. The first vulnerability is a padding oracle attack that allows attackers to extract information about the encryption. The second vulnerability is the ability to execute code on the server through manipulated data. TantoSec has emphasized that the exploit only works against applications running in a specific, non-standard configuration.
This means that many companies using standard configurations are not affected. Nevertheless, it is recommended to check all systems for the latest security updates. The release of the exploit has raised concerns in the security community. Experts advise reviewing security policies and ensuring that all software components are up to date. The potential for exploitation could pose significant risks, particularly for companies reliant on Telerik UI.
Progress has stated that customer security is a top priority. The company has informed all affected customers about the vulnerability and provided the necessary steps to address the security flaw. Security updates are available for all affected versions of Telerik UI. The vulnerability has been registered under the CVE number CVE-2026-12345. Security researchers recommend that companies using Telerik UI promptly update their systems to the latest versions to prevent potential attacks.
The exact number of affected systems is currently unknown; however, it is estimated that several thousand applications worldwide could be impacted. The security situation remains tense, as the release of the exploit may lead to an increased number of attacks. Security analysts are closely monitoring the situation and warning of possible attacks targeting unprotected systems. Therefore, companies should take proactive measures to protect their systems. TantoSec has announced that it will release further details on the technical aspects of the exploit in the coming weeks.
This could provide additional information for companies looking to adjust their security strategies. The release of the proof-of-concept has already sparked intense discussions about the security of web applications. The vulnerability in Telerik UI is an example of the challenges companies face in the field of cybersecurity. Attackers often exploit known vulnerabilities to infiltrate systems.
Therefore, it is crucial for companies to continuously review and adjust their security practices. Progress's security updates have been available since July 15, 2026. Companies that have not yet installed the updates should do so immediately to protect their systems.
💬 Comentarii (0)
Inca nu exista comentarii. Fii primul!