logo

Progress warns of critical RCE bug in Telerik Report Server

ID: 94eed1a7-72a0-59aa-aef1-8cbfde2dbe7a

STIX ID: report--94eed1a7-72a0-59aa-aef1-8cbfde2dbe7a

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-07-25

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Progress Software disclosed CVE-2024-6327, a critical deserialization-based remote code execution vulnerability in Telerik Report Server affecting versions up to 2024 Q2 (10.1.24.514) and patched in 10.1.24.709; administrators are urged to upgrade immediately or apply a temporary mitigation by running the Report Server App Pool under a low-privilege account. The advisory notes related PoC exploit activity chaining other Telerik flaws, historical attacks exploiting older Telerik vulnerabilities, but does not confirm active exploitation of CVE-2024-6327 in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.