logo

Progress discloses second critical flaw in Telerik Report Server in as many months

ID: 8cb6a361-259d-58ff-9d12-137a90eb9525

STIX ID: report--8cb6a361-259d-58ff-9d12-137a90eb9525

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-07-26

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Progress/Telerik disclosed multiple severe vulnerabilities in Telerik Report Server and Reporting—CVE-2024-6327 (insecure deserialization, CVSS 9.9) enabling RCE on affected versions and CVE-2024-6096 (unsafe type resolution, CVSS 8.8) also leading to potential RCE—with upgrades required to fixed versions; the advisory notes the real-world risk given past exploitation of a related deserialization bug by threat actors against US federal targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.