<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Padding-Oracle on CuraSec</title><link>https://curasec.metacog.co.kr/tags/padding-oracle/</link><description>Recent content in Padding-Oracle on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 07 Sep 2026 16:27:04 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/padding-oracle/index.xml" rel="self" type="application/rss+xml"/><item><title>Telerik UI Padding-Oracle Chained to Unauthenticated RCE — PoC Public</title><link>https://curasec.metacog.co.kr/insights/2026-09-07-telerik-ui-padding-oracle-bug-chained-to-unauthenticated-rce/</link><pubDate>Mon, 07 Sep 2026 16:27:04 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-07-telerik-ui-padding-oracle-bug-chained-to-unauthenticated-rce/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A working unauthenticated RCE exploit chain against Telerik UI for ASP.NET AJAX is now public; apply the July Progress patch immediately and audit whether any deployments use the affected non-default AES-CBC configuration that enables the oracle.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No confirmed wild exploitation or published IOCs yet, but the public PoC warrants building detections for anomalous HTTP requests targeting Telerik AJAX endpoints — prepare Sigma/SPL rules now so you&amp;rsquo;re ready if exploitation picks up.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>