CISA has added CVE‑2021‑23758 to its Known Exploited Vulnerabilities catalogue, affecting the Ajax.NET Professional product from Ajax.NET Professional. The vulnerability, named Ajax.NET Professional Deserialization of Untrusted Data Vulnerability, allows remote code execution via arbitrary .NET classes when untrusted data is deserialized.
The flaw is a deserialization of untrusted data issue that can be triggered by sending specially crafted input to an affected .NET application, enabling an attacker to execute code remotely. It carries a CVSS v3 score of 8.1, rated HIGH, and a patch is available through the vendor’s GitHub commit (b0e63be5f0bb20dfce507cb8a1a9568f6e73de57).
Active exploitation has been confirmed in the wild, which is the basis for its inclusion in the KEV catalogue; there is no publicly known use in ransomware campaigns at this time. CISA has set a remediation deadline of 2026‑09‑09 for federal agencies to address the issue.
CISA requires FCEB organisations to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines; all other organisations should review their exposure to Ajax.NET Professional and apply the patch or discontinue use if mitigations cannot be implemented.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2021-23758 and the CISA KEV catalogue.