
Telerik UI Flaws Chain AES-CBC Padding Oracle to Unauthenticated Remote Code Execution
A newly disclosed chain of vulnerabilities in Telerik UI for ASP.NET AJAX can turn an unauthenticated AES-CBC padding oracle into remote code execution (RCE) on susceptible web applications. The issue affects Telerik UI for ASP.NET AJAX releases from 2010.1.309 through 2026.2.519; Progress Software says version 2026.2.708 (2026 Q2 SP1) prevents exploitation of the chain. Security […]
The post Telerik UI Flaws Chain AES-CBC Padding Oracle to Unauthenticated Remote Code Execution appeared first on Cyber Security News.