← Vulnerability feed

Vulnerability record · CVE-2021-23758 · published 3 December 2021

CVE-2021-23758: Ajax.NET Professional ajaxpro.2 untrusted deserialization RCE

AAjaxpro.2 Project · Ajaxpro.2

All versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That lets an attacker craft a malicious payload that executes code on the server. The flaw is remotely reachable without authentication, so any exposed instance is a serious risk.

9.8 CVSS 3.1 Critical CISA KEV since 26 Aug 2026 EPSS 83% · top 0.3% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
83%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
8References, 3 tagged exploit
27 Aug 2026Last modified by NVD

Description

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing and very high EPSS probability makes this an urgent patch-first item.

What it is

All versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That lets an attacker craft a malicious payload that executes code on the server. The flaw is remotely reachable without authentication, so any exposed instance is a serious risk.

Impact

An unauthenticated attacker can achieve remote code execution in the context of the web application, leading to full compromise of the host and any data or credentials it can reach.

Attack surface

Reached over the network via the Ajax.NET HTTP endpoint that processes serialized requests; the CVSS vector shows no privileges and no user interaction required. Any internet- or network-exposed deployment of the package is in scope.

Exploitation

CISA added it to KEV with a 2026-09-09 remediation due date, and public exploit code exists (Packet Storm, Talos blog reference). EPSS is 0.83633 (99.7th percentile), indicating very high likelihood of exploitation activity.

What to do

  • Apply the vendor patch from the Ajax.NET Professional commit b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 or upgrade to a fixed release.
  • If no fixed version is available for your deployment, remove or disable the ajaxpro.2 handler and discontinue use of the product per CISA BOD 26-04 guidance.
  • Restrict network access to Ajax.NET endpoints so only trusted clients can reach them; do not expose them to the internet.
  • Enforce .NET deserialization protections (type allow-listing, disabling unsafe binders) where the framework permits.
  • Inventory all applications referencing ajaxpro.2 or Ajax.NET Professional and prioritize internet-facing instances for immediate remediation.

Detection

  • Search web/proxy logs for POST requests to Ajax.NET handler paths with unusually large or binary-looking bodies.
  • Monitor for w3wp.exe or the application process spawning child processes such as cmd.exe, powershell.exe or net.exe.
  • Look for .NET deserialization gadget artifacts or known ysoserial.net payload markers in request bodies.
  • Alert on outbound connections from web servers to new or unusual destinations following Ajax endpoint traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-23758 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 9 September 2026.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23758 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.4CVE-2023-49289Michaelschwarz ajax.net professional cross-site scripting vulnerabilityAjax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to…EPSS 0.63%9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed9.3CVE-2026-45247Mirasvit Full Page Cache Warmer for Magento 2 PHP object injection RCEMirasvit Full Page Cache Warmer for Magento 2 before 1.11.12 passes the CacheWarmer cookie to PHP's native unserialize() without restriction, allowin…KEVEPSS 2.1%analysed8.8CVE-2023-21529Microsoft Exchange Server deserialization flaw enables remote code executionCVE-2023-21529 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Exchange Server that allows remote code execution. It carr…KEVEPSS 59%analysed

Source: NIST National Vulnerability Database (record CVE-2021-23758), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.