CVE-2021-23758 KEV
8.1
HIGH · CVSS 3.1 · EPSS 82.6% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2026-09-09.
Description
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Scoring
| CVSS | 8.1 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 82.58% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-502 |
| On CISA KEV | yes — remediate by 2026-09-09 |
| Public exploit | none known |
| Published | 2021-12-03 |
| Last modified | 2026-08-27 |
CISA KEV
| Name | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability |
|---|---|
| Added | 2026-08-26 |
| Due | 2026-09-09 |
| Vendor / product | Ajax.NET Professional / Ajax.NET Professional |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| ajaxpro.2 project | ajaxpro.2 |
| michaelschwarz | ajax.net professional |
References
- http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
- https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
- https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971
- http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
- https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
- https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758
→ the Explorer · watch your stack · NVD