[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f61g-cibRzfFAp96lm194qHKRLatjOVEphn5ooHOFHzk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"fdc4e036-3691-4275-830b-0a9eb9a858b6","public-exploit-raises-stakes-for-unpatched-telerik-ui-installations","3776b0a4-7dc4-4eff-b4cf-2f6aff5b34e2","Public Exploit Raises Stakes for Unpatched Telerik UI Installations","A proof-of-concept exploit chain has been publicly released targeting Telerik UI for ASP.NET AJAX, enabling unauthenticated remote code execution by chaining an AES-CBC padding oracle vulnerability. Although Progress Software issued patches in July, organizations that have not applied them are now at significantly elevated risk due to the public availability of a ready-to-use exploit tool. The vulnerability is triggered by a non-default configuration, highlighting how insecure or legacy configuration choices can expand attack surface in widely deployed third-party UI components. Public exploit releases dramatically compress the window between patch availability and active exploitation, meaning delayed patching is no longer a tolerable risk posture. This incident underscores the danger of relying on obscurity when a vendor patch already exists.","**Immediate actions:**\n- Apply the Progress Software patch released in July immediately to all instances of Telerik UI for ASP.NET AJAX across your environment.\n- Audit all deployments for the non-default configuration that enables the vulnerable code path and remediate or disable it where the patch cannot be applied immediately.\n- Use a web application firewall (WAF) rule to detect and block padding-oracle and suspicious serialization request patterns targeting Telerik endpoints.\n\n**Long-term improvements:**\n- Maintain a comprehensive, up-to-date software bill of materials (SBOM) that includes all third-party UI libraries and components to enable rapid identification of affected systems during future disclosures.\n- Establish an SLA-driven emergency patching process that mandates critical vulnerability remediation within 24–72 hours for internet-facing systems.\n- Enforce hardened, documented baseline configurations for all third-party components and validate them continuously through configuration scanning tools.\n\n**Detection measures:**\n- Deploy runtime application self-protection (RASP) or enhanced logging on ASP.NET applications to detect anomalous deserialization or unexpected code execution attempts.\n- Configure SIEM alerting for unusual HTTP response patterns (e.g., padding-oracle timing anomalies) on web application endpoints.\n- Subscribe to vendor security advisories and threat intelligence feeds to receive advance warning of newly published exploit code for products in your environment.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 CM-6: Configuration Settings","NIST SP 800-53 RA-5: Vulnerability Monitoring and Scanning","NIST SP 800-53 SI-10: Information Input Validation","NIST CSF ID.AM-2: Software platforms and applications are inventoried","NIST CSF RS.MI-3: Newly identified vulnerabilities are mitigated","OWASP A06:2021 – Vulnerable and Outdated Components","ITIL Change Management: Emergency Change procedures for critical patches","GDPR Article 32: Security of processing (applicable if personal data is exposed)","published","2026-09-07T14:22:30.73436+00:00","2026-09-07T14:22:30.638+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Ftelerik-ui-padding-oracle-bug-chained.html","telerik-ui-padding-oracle-bug-chained-to-unauthenticated-rce-public-exploit-rele-ff2a8e","Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":45,"name":46,"slug":47,"description":48,"color":49},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]