Security Firm Releases Public Exploit for Telerik UI Vulnerabilities
AI-generated from multiple sources. Verify before acting on this reporting.
LONDON (AP) — Security research firm TantoSec released a public exploit chain on Monday targeting unauthenticated remote code execution vulnerabilities in Progress Software's Telerik UI for ASP.NET AJAX, exposing a critical risk to enterprise web applications. The disclosure, made on Sept. 7, 2026, details a complete attack path that allows malicious actors to execute arbitrary code on victim servers without requiring prior authentication or user interaction.
The vulnerability stems from a combination of flaws within the Telerik UI suite, specifically involving a padding oracle weakness and an unguarded type-resolution mechanism in the RadAsyncUpload control. TantoSec demonstrated how these distinct issues can be chained together to bypass security controls and compromise systems running vulnerable versions of the software. The exploit chain effectively turns the file upload functionality into a vector for remote code execution, potentially allowing attackers to take full control of affected servers.
Progress Software, the developer of the Telerik UI suite, has not yet issued a public statement regarding the specific details of the newly released exploit or the timeline for a patch. The software is widely used by organizations globally to build and manage web applications, making the unauthenticated nature of the flaw particularly concerning for system administrators. Without immediate mitigation, any server running an affected version of the Telerik UI for ASP.NET AJAX remains susceptible to automated scanning and exploitation.
The release of the exploit code marks a significant escalation in the threat landscape surrounding this software component. Unlike previous advisories that warned of potential risks, TantoSec has provided functional proof-of-concept code that outlines exactly how the attack is executed. This level of detail enables security teams to test their environments for exposure but also lowers the barrier for malicious actors seeking to weaponize the vulnerabilities.
Security experts urge organizations utilizing Telerik components to review their configurations immediately and apply any available patches or workarounds. Until a definitive fix is deployed by Progress Software, administrators may need to implement network-level restrictions or disable the RadAsyncUpload control entirely to prevent unauthorized access. The widespread adoption of the software means that the impact of this vulnerability could extend across numerous sectors, including finance, healthcare, and government.
Questions remain regarding the full scope of systems currently exposed and whether any active exploitation has already occurred in the wild prior to the public release of the exploit chain. As researchers continue to analyze the implications of the padding oracle and type-resolution flaws, the cybersecurity community awaits a formal response from Progress Software outlining remediation steps for affected users.