Vulnerability record · CVE-2021-23758 · published 3 December 2021
CVE-2021-23758: Ajax.NET Professional ajaxpro.2 untrusted deserialization RCE
AAjaxpro.2 Project · Ajaxpro.2
All versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That lets an attacker craft a malicious payload that executes code on the server. The flaw is remotely reachable without authentication, so any exposed instance is a serious risk.
Description
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a 9.8 CVSS score, KEV listing and very high EPSS probability makes this an urgent patch-first item.
What it is
All versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That lets an attacker craft a malicious payload that executes code on the server. The flaw is remotely reachable without authentication, so any exposed instance is a serious risk.
Impact
An unauthenticated attacker can achieve remote code execution in the context of the web application, leading to full compromise of the host and any data or credentials it can reach.
Attack surface
Reached over the network via the Ajax.NET HTTP endpoint that processes serialized requests; the CVSS vector shows no privileges and no user interaction required. Any internet- or network-exposed deployment of the package is in scope.
Exploitation
CISA added it to KEV with a 2026-09-09 remediation due date, and public exploit code exists (Packet Storm, Talos blog reference). EPSS is 0.83633 (99.7th percentile), indicating very high likelihood of exploitation activity.
What to do
- Apply the vendor patch from the Ajax.NET Professional commit b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 or upgrade to a fixed release.
- If no fixed version is available for your deployment, remove or disable the ajaxpro.2 handler and discontinue use of the product per CISA BOD 26-04 guidance.
- Restrict network access to Ajax.NET endpoints so only trusted clients can reach them; do not expose them to the internet.
- Enforce .NET deserialization protections (type allow-listing, disabling unsafe binders) where the framework permits.
- Inventory all applications referencing ajaxpro.2 or Ajax.NET Professional and prioritize internet-facing instances for immediate remediation.
Detection
- Search web/proxy logs for POST requests to Ajax.NET handler paths with unusually large or binary-looking bodies.
- Monitor for w3wp.exe or the application process spawning child processes such as cmd.exe, powershell.exe or net.exe.
- Look for .NET deserialization gadget artifacts or known ysoserial.net payload markers in request bodies.
- Alert on outbound connections from web servers to new or unusual destinations following Ajax endpoint traffic.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-23758 to the Known Exploited Vulnerabilities catalog on 26 August 2026 as "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 9 September 2026.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html | ExploitVDB Entry |
| https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 | PatchThird Party Advisory |
| https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971 | Third Party Advisory |
| http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html | ExploitVDB Entry |
| https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 | PatchThird Party Advisory |
| https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971 | Third Party Advisory |
| https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-opera | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758 | US Government Resource |
Track CVE-2021-23758 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-23758), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.