live feed
The Hacker News
7 Sept 2026

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progres

// analyst note

This briefing summarises reporting from The Hacker News. 90@! Ltd curates and rewrites third-party cybersecurity reporting for UK defenders. For the full technical write-up, read the original source.

Curated by 90@! Ltd from The Hacker News. Read the original for full technical detail.

Read original at The Hacker News

// 90@! Ltd

Need help acting on this?

90@! Ltd is a UK applications and cybersecurity consultancy. We help teams triage, remediate, and harden against emerging threats like this one.

Start an engagement