• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2021-23758: pre-auth remote code execution in Ajax.NET Professional Ajax.NET Professional

Remote attackers can execute arbitrary code against Ajax.NET Professional by sending crafted data that triggers unsafe .NET deserialization. This is tracked as CVE-2021-23758 and affects the AjaxPro.2 branch (versions before the vendor fix; fixed version not specified in vendor data). Exploitation requires only network access to the vulnerable service and no authentication or user interaction, allowing unauthenticated remote code execution if the component is reachable.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.82578
CWE
CWE-502
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this vulnerability is in CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-09-09, and public exploit code exists — reduce exposure immediately and apply vendor guidance without delay.

What is CVE-2021-23758?

Remote attackers can execute arbitrary code against Ajax.NET Professional by sending crafted data that triggers unsafe .NET deserialization. This is tracked as CVE-2021-23758 and affects the AjaxPro.2 branch (versions before the vendor fix; fixed version not specified in vendor data). Exploitation requires only network access to the vulnerable service and no authentication or user interaction, allowing unauthenticated remote code execution if the component is reachable. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Ajax.NET Professional Ajax.NET Professional are affected?

BRANCHAFFECTEDFIXED
AjaxPro.2before unspecifiedunspecified

Is CVE-2021-23758 being exploited?

CISA added CVE-2021-23758 to the Known Exploited Vulnerabilities catalog on 2026-08-26, and U.S. federal agencies must remediate it by 2026-09-09.

How to fix CVE-2021-23758

  1. Follow the vendor’s mitigation and update instructions immediately (apply vendor-supplied fixes if available).
  2. If a vendor-fixed version is not identified, restrict network exposure: block access to the Ajax.NET endpoints from untrusted networks and limit to trusted management hosts.
  3. Monitor application and host logs for suspicious activity and indicators of compromise related to .NET deserialization and unexpected process starts.
  4. If you cannot mitigate or patch, discontinue use of the affected AjaxPro.2 component until a secure version or guidance is available.

Frequently asked questions

Is CVE-2021-23758 being actively exploited?

CISA added CVE-2021-23758 to its Known Exploited Vulnerabilities catalog on 2026-08-26, requiring federal remediation by 2026-09-09.

Which Ajax.NET Professional versions are affected by CVE-2021-23758?

The vulnerability affects the AjaxPro.2 branch prior to the vendor fix; the specific fixed version is not specified in the provided data.

Is there a patch for CVE-2021-23758?

Patch availability is indicated as true in the vendor data, but the exact fixed version is not specified; follow the vendor’s published update instructions.

Does CVE-2021-23758 require authentication?

No; the vulnerability allows unauthenticated remote code execution against Ajax.NET Professional when the vulnerable endpoint is network-accessible.

References