EPSS Alert: The probability of this vulnerability being exploited within the next 30 days is 89.1% (percentile: 100%). That is among the highest scores that occur at all.
Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2021-23758 |
| Alert Source | CISA KEV - Active Exploitation |
| CVE Year | 2021 |
| Publication Date | 2026-08-26 |
| Vendor | Michael Schwarz |
| Product | Ajax.NET Professional (AjaxPro), ajaxpro.2 package |
| CVSS Score | 8.1 (High) |
| EPSS Score | 89.1% (percentile: 100%) |
| CISA KEV | Yes - confirmed active exploitation |
| Ransomware | Not confirmed |
| Due Date | 2026-09-09 |
Vulnerability Description
Source: CISA KEV / NVD
All versions of the ajaxpro.2 package (Ajax.NET Professional, or AjaxPro) are vulnerable to deserialization of untrusted data. The library deserializes arbitrary attacker-supplied .NET classes, which can be abused to achieve remote code execution on the application server.
The product is no longer supported — CISA classifies it as end-of-life / end-of-service. There is no patch to apply. The only effective response is removing the library from the application or migrating to a supported AJAX call mechanism.
The combination of 89% EPSS and KEV status means this is not a theoretical risk: the vulnerability is being exploited at scale, and attacker scanners look for it deliberately.
Required Actions
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 “Prioritizing Security Updates Based on Risk” guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Because the library is unsupported, the order of operations differs from ordinary patching:
- Determine whether
ajaxpro.2(orAjaxPro.dll) appears in any maintained .NET application — including ones nobody actively develops. - If so, cut off access to AjaxPro endpoints from untrusted networks before planning removal.
- Plan migration or decommissioning. There is no version to upgrade to.
CISA’s deadline for US federal agencies: 2026-09-09.
Who Is Affected?
The vulnerability affects ASP.NET applications using the Ajax.NET Professional (AjaxPro) library in any version.
This is a library from the early ASP.NET era — today found almost exclusively in legacy applications that still run because they carry a business process, but have no active development team. Such applications are genuinely present in finance, insurance and public administration, where internal systems live for a decade or more. It is worth checking the application inventory for the mere presence of AjaxPro.dll — the high EPSS score means the window for reacting is short.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
