logo

Exploit for critical Progress Telerik auth bypass released, patch now

ID: 8c0013ad-fb59-5acc-a99a-51d23d4c4c65

STIX ID: report--8c0013ad-fb59-5acc-a99a-51d23d4c4c65

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers published a PoC exploit that chains an authentication bypass (CVE-2024-4358, CVSS 9.8) and a deserialization RCE (CVE-2024-1800, CVSS 8.8) in Progress Telerik Report Server to achieve remote code execution; Progress has released patches (upgrade to 10.1.24.514 or later) and advises administrators to apply updates and review local user accounts for unexpected additions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.