The Telerik exploit chain needs the hardening step Telerik recommends
2026-09-07Security
TantoSec released a working exploit on 7 September for a padding-oracle chain in Telerik's RadAsyncUpload control that ends in unauthenticated code execution. Its precondition is an explicit, non-default encryption key — the setting administrators were told to configure. Roughly 127,000 requests and an hour in a lab.