CVE-2021-23758
Deserialization of Untrusted Data
Exploited in the wild. In CISA KEV since 2026‑08‑26. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether your website/app is using AjaxNetProfessional, AjaxPro.2, or ajax.net professional, and identify the exact installed version.
- If you use ajaxnetprofessional, upgrade it to fixed version 21.11.29.1.
- If you use ajax.net professional, upgrade it to fixed version 21.10.30.1.
- If you use AjaxPro.2 and you cannot confirm the version is fixed by your vendor, treat it as vulnerable until you get an explicit “fixed in …” version from your software vendor.
- After upgrading, verify the server is not still reachable with the vulnerable component and review server logs for signs of unusual requests around the time of the change.
What it is
From the CVE record
Remote Code Execution in AjaxNetProfessional
In plain language
Written by AI from the recordCVE-2021-23758 lets anyone on the network send malicious data to AjaxNetProfessional/AjaxPro.2 and potentially take full control of the server without a login—small businesses using affected versions should act urgently.
CVE-2021-23758 is an unauthenticated remote code execution issue caused by the server deserializing untrusted network data (CWE-502), which allows an attacker to send crafted input to run arbitrary code on AjaxNetProfessional/AjaxPro.2 systems.
If you're affected
- Full server takeover
- Business systems shut down
- Data theft from the server
- Ransomware-ready conditions
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-08-26.
US federal agencies must remediate by 2026-09-09.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
1 source with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
83% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
The patch came 471 days before any public exploit.
- Analysis publishedCISA's Newest KEV Batch Has an 11-Year-Old Bug in It — But Not All Six Are the Same Story
- Patch availablerecord updated
- Added to CISA KEVpatch available, record updated
- Public exploit / PoCsource: packetstorm
- Patch availablerecord updated
- Publishedweakness classified, att&ck mapped
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored 8.1 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity HighRequires specific conditions like a race condition or non-default configuration
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
- github.com/michaelschwarz/Ajax.NET-Professional/security/advisories/GHSA-6r7c-6w96-8pvw
- nvd.nist.gov/vuln/detail/CVE-2021-23758
- github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
And 6 more references. See all after sign-in
In the news
- Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for AjaxNetProfessional, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI