Find notable cyber news and cases, enriched with sources, timelines, and signals.

Telerik UI for ASP.NET AJAX RadAsyncUpload padding-oracle RCE chain (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

A Telerik UI for ASP.NET AJAX RadAsyncUpload flaw chain can lead to unauthenticated remote code execution when a non-default encryption-key configuration is present. The public release adds a working padding-oracle exploit, a command-line tool, and payloads for the 2026.2.708-patched vulnerability set. Progress Software says affected versions run from 2010.1.309 through 2026.2.519, while 2026.2.708 and later are fixed.

Related Happenings

CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962

Public Sector Action
H score49 First: 25.08.2026 09:12 Last: 25.08.2026 09:12 Sources 1

About this happening: CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. Th...

CISA BOD 26-04 Oracle EBS patch order

Public Sector Action
H score38 First: 16.07.2026 13:56 Last: 16.07.2026 13:56 Sources 1

About this happening: CISA ordered U.S. government agencies to patch vulnerable Oracle E-Business Suite instances by Saturday, July 18, tightening federal exposure to an actively expl...

Timeline

  1. 07.09.2026 14:20 2 articles · 3h ago

    TantoSec releases telerik-rau-exploit and payloads for Telerik UI for ASP.NET AJAX

    Initial Disclosure

    TantoSec publishes the exploit method for Telerik UI for ASP.NET AJAX and releases telerik-rau-exploit with two mixed-mode DLL payloads, enabling a padding-oracle chain that can lead to unauthenticated remote code execution when the non-default RadAsyncUpload configuration is present.

    Show sources