peter bassill · operator
$ cve CVE-2021-23758 JSON

CVE-2021-23758 KEV

8.1
HIGH · CVSS 3.1 · EPSS 82.6% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-09.

Description

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS82.58% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2026-09-09
Public exploitnone known
Published2021-12-03
Last modified2026-08-27

CISA KEV

NameAjax.NET Professional Deserialization of Untrusted Data Vulnerability
Added2026-08-26
Due2026-09-09
Vendor / productAjax.NET Professional / Ajax.NET Professional
Ransomware usenone reported

Affected (2)

VendorProduct
ajaxpro.2 projectajaxpro.2
michaelschwarzajax.net professional

References

→ the Explorer  ·  watch your stack  ·  NVD