THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, provides an authoritative source for vulnerabilities exploited in real-world scenarios, aiding organizations in prioritizing their vulnerability management efforts. The catalog includes detailed information about CVE-2021-23758, which affects Ajax.NET Professional and contains a deserialization vulnerability that allows for remote code execution.
Users are urged to either mitigate the risks as per vendor instructions or discontinue use of unpatched products. Stakeholders must evaluate their internet exposure and adhere to CISA's patching guidelines, including BOD-26-04. The catalog is accessible in various formats, including CSV and JSON.