ICS/OT

Progress Patches Critical Telerik Report Server Vulnerability

Progress Software calls attention to a critical remote code execution flaw in the Telerik Report Server product.

Progress Software calls attention to a critical remote code execution flaw in the Telerik Report Server product.

Progress Software has issued an advisory to call attention to a critical-severity vulnerability in its Telerik Report Server product and warned that the issue could be exploited for remote code execution (RCE).

The issue, tracked as CVE-2024-6327 (CVSS score of 9.9/10), is described as an insecure deserialization flaw affecting Telerik instances prior to 2024 Q2 (10.1.24.709).

“In Progress Telerik Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through CVE-2024-6096,” the company said in an advisory.

Remote attackers could exploit the deserialization of untrusted data to inject malicious objects and execute arbitrary code on the underlying server. Authentication is not required for the successful exploitation of the vulnerability.

Progress has addressed the issue in Telerik Report Server version 2024 Q2 (10.1.24.709) and urges users to update their deployments as soon as possible.

“Updating to Report Server 2024 Q2 (10.1.24.709) or later is the only way to remove this vulnerability. The Progress Telerik team strongly recommends performing an upgrade to the latest version,” the company added.

Advertisement. Scroll to continue reading.

As a temporary mitigation, administrators could change the user for the Report Server Application Pool to one that has limited permissions. Details on how to change the IIS user for the Report Server can be found in this knowledge base article.

Telerik Report Server users are advised to update their instances as soon as possible. Threat actors are known to have exploited Telerik vulnerabilities as well, including in attacks targeting a US government agency.

Last month, Progress patched another critical flaw in the server, and the US cybersecurity agency CISA warned of its exploitation less than ten days later.

An end-to-end report management solution, Telerik Report Server helps businesses convert raw data into actionable insights that can be distributed within the organization.

Related: Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products

Related: Docker Patches Critical AuthZ Plugin Bypass Vulnerability Dating Back to 2018

Related: SolarWinds Patches Critical Vulnerabilities in Access Rights Manager

Related Content

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

Vulnerabilities

The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.

ICS/OT

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

Risk Management

Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.

Vulnerabilities

The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it.

Vulnerabilities

The company notified customers to manually shut down their servers while it is investigating a credible threat.

Vulnerabilities

Two newly disclosed critical vulnerabilities in Adobe ColdFusion and Langflow join two Joomla extension flaws in CISA's Known Exploited Vulnerabilities catalog, with federal agencies...

Government

The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version