September 8, 2026
- TantoSec published a working exploit chain turning an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated RCE — but only against applications in a specific non-default configuration. Progress patched the chain in July and there are no confirmed reports of in-the-wild exploitation (The Hacker News). · New Tools & Releases
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited