Back to News
Cybersecurity

Telerik UI Vulnerability Exposes Businesses to Remote Code Execution Risks

TantoSec reveals a proof-of-concept exploit for a Telerik UI vulnerability that could lead to unauthenticated remote code execution.

A recent announcement from security firm TantoSec has highlighted a critical vulnerability in Telerik UI for ASP.NET AJAX, demonstrating how an AES-CBC 'padding oracle' issue can be exploited to achieve unauthenticated remote code execution (RCE). This exploit relies on specific, non-default configurations of the applications, and while Progress Software has issued a patch for this vulnerability back in July, the release of the proof-of-concept (PoC) exploit raises significant concerns about the security posture of businesses relying on this framework. Notably, there are currently no confirmed instances of this exploit being utilized in the wild, but the potential for risk remains concerning.

For businesses using Telerik UI, the implications are clear: immediate attention to application configurations and ensuring that all updates from Progress Software are applied promptly is critical to mitigate the risk of exploitation. The release of this exploit underscores the importance of proactive vulnerability management and highlights the need for organizations to regularly review their security practices. As cyber threats continue to evolve, this incident serves as a reminder of the vulnerabilities inherent in widely-used frameworks and the necessity for robust security measures. This is particularly relevant in the context of AI and cybersecurity, as the integration of AI-driven solutions in business operations necessitates a heightened focus on security to prevent exploitation of such vulnerabilities.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html)*