CISA added CVE-2021-23758, a deserialization of untrusted data vulnerability in Ajax.NET Professional (AjaxPro), to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation due date of 2026-09-09.
What Is It
All versions of the ajaxpro.2 package are vulnerable to Deserialization of Untrusted Data (CWE-502) due to the possibility of deserializing arbitrary .NET classes, which can be abused to gain remote code execution.
NVD's primary CVSS 3.1 score is 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The secondary score from the reporting source (Snyk) is 8.1 (HIGH), differing only on attack complexity (AC:H). Both agree on network attack vector, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.
Why It Matters
CISA's KEV listing confirms active exploitation. The accompanying SSVC decision point set records exploitation: active, automatable: no, and technicalImpact: total. Known ransomware campaign use is listed as Unknown.
Public exploit material exists: NVD references a Packet Storm entry titled "AjaxPro Deserialization Remote Code Execution," tagged as an Exploit. NVD also cites Cisco Talos reporting on UAT-10147, a Chinese-speaking adversary integrating agentic AI into post-compromise operations, as an exploit-tagged reference for this CVE.
CISA notes this vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products; meaning exposure may extend beyond direct AjaxPro deployments.
What's Vulnerable
ajaxpro.2, all versions (cpe:2.3:a:ajaxpro.2_project:ajaxpro.2:*:*:*:*:*:.net:*:*)- Michael Schwarz Ajax.NET Professional; versions before 21.10.30.1 (
cpe:2.3:a:michaelschwarz:ajax.net_professional:*:*:*:*:*:.net:*:*)
Patch Status
An upstream fix exists in commit b0e63be of the Ajax.NET-Professional repository, and NVD's configuration data indicates versions from 21.10.30.1 onward are outside the vulnerable range.
CISA warns the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS), and advises users to discontinue use and/or transition to a supported version.
Required action (due 2026-09-09): Apply mitigations per vendor instructions in compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758
- NVD, CVE-2021-23758, https://nvd.nist.gov/vuln/detail/CVE-2021-23758
- Upstream patch commit (Ajax.NET-Professional), https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
- Snyk advisory SNYK-DOTNET-AJAXPRO2-1925971; https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971
- Packet Storm, AjaxPro Deserialization Remote Code Execution, http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
- Cisco Talos, UAT-10147 agentic AI post-compromise operations, https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance / Forensics Triage Requirements; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk