Threat+Constellation
Live UTC
← Incidents
INCIDENT 280Exploited vulnerabilityHIGH CONFIDENCESourced

CVE-2021-23758 added to CISA KEV: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

<p>CISA has added six new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <div class="ListContainerWrapper SCXW183571888 BCX8"> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2015-3246" target="_blank">CVE-2015-3246</a> Red Hat Libuser Race Condition Vulnerability</li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2015-5287" target="_blank">CVE-2015-5287</a> Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability</li> <li><a…

Last evidence update
26 AUG 2026 · 12:00 UTC
Source count
3
Status
high confidence
LogisticsGovernmentCVE-2021-23758CVE-2015-3246CVE-2015-5287CVE-2019-1068CVE-2022-0995CVE-2026-8452
Observation history

How this record has evolved as evidence accumulated.

27 AUG · 05:21 UTC
Initial report
27 AUG · 05:21 UTC
Second independent source
27 AUG · 05:21 UTC
Confidence upgraded
27 AUG · 05:21 UTC
Status changed
27 AUG · 05:21 UTC
Second independent source
27 AUG · 05:21 UTC
Summary updated from new evidence
27 AUG · 05:21 UTC
Related CVE identified (CVE-2026-8452)
Evidence
Related incidents