Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-27 ยท updated: 2026-08-27 ยท tags: [cve, deserialization, kev, rce] ยท confidence: high ยท severity: high ยท affected_sectors: [technology] ยท au_impact: false

CVE-2021-23758 โ€” Ajax.NET Professional Deserialisation Vulnerability

CVE-2021-23758 is a deserialisation-of-untrusted-data vulnerability in Ajax.NET Professional. It was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2026-08-26 based on evidence of active exploitation. Deserialisation flaws of this kind can allow remote code execution when a vulnerable application processes untrusted objects, making them a persistent initial-access vector for web applications.

Type: Deserialisation of untrusted data | Exploitation: Active | Mitigation: patch the hosting application; audit legacy .NET webapps