DIRAS TAKE
Urgent: this vulnerability is in CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-09-09, and public exploit code exists — reduce exposure immediately and apply vendor guidance without delay.
What is CVE-2021-23758?
Remote attackers can execute arbitrary code against Ajax.NET Professional by sending crafted data that triggers unsafe .NET deserialization. This is tracked as CVE-2021-23758 and affects the AjaxPro.2 branch (versions before the vendor fix; fixed version not specified in vendor data). Exploitation requires only network access to the vulnerable service and no authentication or user interaction, allowing unauthenticated remote code execution if the component is reachable. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Ajax.NET Professional Ajax.NET Professional are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| AjaxPro.2 | before unspecified | unspecified |
Is CVE-2021-23758 being exploited?
CISA added CVE-2021-23758 to the Known Exploited Vulnerabilities catalog on 2026-08-26, and U.S. federal agencies must remediate it by 2026-09-09.
How to fix CVE-2021-23758
- Follow the vendor’s mitigation and update instructions immediately (apply vendor-supplied fixes if available).
- If a vendor-fixed version is not identified, restrict network exposure: block access to the Ajax.NET endpoints from untrusted networks and limit to trusted management hosts.
- Monitor application and host logs for suspicious activity and indicators of compromise related to .NET deserialization and unexpected process starts.
- If you cannot mitigate or patch, discontinue use of the affected AjaxPro.2 component until a secure version or guidance is available.
Frequently asked questions
Is CVE-2021-23758 being actively exploited?
CISA added CVE-2021-23758 to its Known Exploited Vulnerabilities catalog on 2026-08-26, requiring federal remediation by 2026-09-09.
Which Ajax.NET Professional versions are affected by CVE-2021-23758?
The vulnerability affects the AjaxPro.2 branch prior to the vendor fix; the specific fixed version is not specified in the provided data.
Is there a patch for CVE-2021-23758?
Patch availability is indicated as true in the vendor data, but the exact fixed version is not specified; follow the vendor’s published update instructions.
Does CVE-2021-23758 require authentication?
No; the vulnerability allows unauthenticated remote code execution against Ajax.NET Professional when the vulnerable endpoint is network-accessible.
References
- nvd.nist.gov/vuln/detail/CVE-2021-23758
- cve.org/CVERecord?id=CVE-2021-23758
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758
- snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971
- github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
- packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
- All Ajax.NET Professional CVEs on CVE Radar
- CVEs published in September 2026