All incidents

CISA adds Ajax.NET Professional deserialization flaw (CVE-2021-23758) to KEV catalogue

vulnerabilityopenAug 26, 2026 — Aug 27, 2026

CISA has placed CVE‑2021‑23758 in its KEV catalogue after confirming that the Ajax.NET Professional deserialization flaw is being exploited in the wild. The addition means organisations using the affected library must treat the issue as a priority for remediation.

The vulnerability carries a CVSS v3 score of 8.1, rated HIGH, and stems from insecure deserialization of untrusted data within Ajax.NET Professional. When a specially crafted payload is sent to a vulnerable .NET application, the flaw permits execution of arbitrary .NET classes, leading to remote code execution. A patch addressing the issue is available in the vendor’s GitHub repository at this commit.

Exploitation occurs when an attacker supplies malicious input that triggers the deserialization process, allowing the attacker to invoke dangerous gadget chains and run code on the server side. Although the original vendor is not publicly named, the fix has been published openly, giving defenders a clear path to mitigation. The flaw affects any deployment that relies on the library for handling AJAX requests in ASP.NET environments.

CISA’s decision to list the flaw follows observed activity in threat feeds, indicating that the vulnerability is already being used as part of intrusion attempts. No specific threat actor has been attributed to the exploits so far, but the presence in the KEV catalogue highlights that the issue is not theoretical. Organisations should therefore assume active risk until the patch is applied.

Defenders should first identify any instances of Ajax.NET Professional within their web applications, particularly those exposed to the internet. Applying the patch from the referenced GitHub commit is the most effective remediation, though temporary mitigations such as restricting deserialization to trusted types or employing input validation can reduce risk while updates are tested. Following CISA’s Binding Operational Directive BOD‑26‑04, organisations should prioritise remediation of KEV‑listed vulnerabilities within the prescribed timeframe.

Maintaining an inventory of third‑party components and subscribing to vulnerability feeds will help catch similar issues early. Monitoring deserialisation endpoints for anomalous traffic can also provide early warning of exploitation attempts. Keeping systems up to date remains the simplest defence against this class of flaw.

Intelligence briefing updated Aug 27, 2026

CVE-2021-23758 8.1 KEV
Root sourcegithub.com
Timeline Coverage

Swipe to explore timeline