Telerik UI for ASP.NET AJAX RadAsyncUpload padding-oracle RCE chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
A Telerik UI for ASP.NET AJAX RadAsyncUpload flaw chain can lead to unauthenticated remote code execution when a non-default encryption-key configuration is present. The public release adds a working padding-oracle exploit, a command-line tool, and payloads for the 2026.2.708-patched vulnerability set. Progress Software says affected versions run from 2010.1.309 through 2026.2.519, while 2026.2.708 and later are fixed.
Related Happenings
CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962
Public Sector Action
H score49
First: 25.08.2026 09:12
Last: 25.08.2026 09:12
Sources 1
About this happening:
CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. Th...
CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962
Public Sector ActionAbout this happening: CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. Th...
CISA BOD 26-04 Oracle EBS patch order
Public Sector Action
H score38
First: 16.07.2026 13:56
Last: 16.07.2026 13:56
Sources 1
About this happening:
CISA ordered U.S. government agencies to patch vulnerable Oracle E-Business Suite instances by Saturday, July 18, tightening federal exposure to an actively expl...
CISA BOD 26-04 Oracle EBS patch order
Public Sector ActionAbout this happening: CISA ordered U.S. government agencies to patch vulnerable Oracle E-Business Suite instances by Saturday, July 18, tightening federal exposure to an actively expl...
Timeline
-
07.09.2026 14:20 1 articles · 3h ago
TantoSec reports RadAsyncUpload chain to Progress Software
Initial DisclosureTantoSec notifies Progress Software about the RadAsyncUpload vulnerability chain in Telerik UI for ASP.NET AJAX, which requires a non-default encryption-key configuration to become exploitable.
Show sources
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released — thehackernews.com — 07.09.2026 14:20
-
07.09.2026 14:20 1 articles · 3h ago
Progress Software ships Telerik UI for ASP.NET AJAX 2026.2.708
Mitigation Patch UpdateProgress Software ships Telerik UI for ASP.NET AJAX 2026.2.708 (2026 Q2 SP1), replacing the flawed AES-CBC scheme with authenticated encryption and fixing the RadAsyncUpload chain.
Show sources
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released — thehackernews.com — 07.09.2026 14:20
-
07.09.2026 14:20 1 articles · 3h ago
Progress Software publishes CVEs and advisory for Telerik UI flaws
Technical Analysis UpdateProgress Software publishes the CVEs and advisory for the Telerik UI for ASP.NET AJAX flaws, documenting the RadAsyncUpload chain and the related fixed versions and affected range.
Show sources
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released — thehackernews.com — 07.09.2026 14:20
-
07.09.2026 14:20 2 articles · 3h ago
TantoSec releases telerik-rau-exploit and payloads for Telerik UI for ASP.NET AJAX
Initial DisclosureTantoSec publishes the exploit method for Telerik UI for ASP.NET AJAX and releases telerik-rau-exploit with two mixed-mode DLL payloads, enabling a padding-oracle chain that can lead to unauthenticated remote code execution when the non-default RadAsyncUpload configuration is present.
Show sources
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released — thehackernews.com — 07.09.2026 14:20
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released — thehackernews.com — 07.09.2026 14:20