Skip to content
Security Alerts

CVE-2021-23758: Untrusted Deserialization in Ajax.NET Professional

All versions of the ajaxpro.2 package deserialize arbitrary .NET classes, allowing remote code execution. The library is no longer supported - discontinuing its use is the recommended path...

EPSS Alert: The probability of this vulnerability being exploited within the next 30 days is 89.1% (percentile: 100%). That is among the highest scores that occur at all.

Summary

ParameterValue
CVE IDCVE-2021-23758
Alert SourceCISA KEV - Active Exploitation
CVE Year2021
Publication Date2026-08-26
VendorMichael Schwarz
ProductAjax.NET Professional (AjaxPro), ajaxpro.2 package
CVSS Score8.1 (High)
EPSS Score89.1% (percentile: 100%)
CISA KEVYes - confirmed active exploitation
RansomwareNot confirmed
Due Date2026-09-09

Vulnerability Description

Source: CISA KEV / NVD

All versions of the ajaxpro.2 package (Ajax.NET Professional, or AjaxPro) are vulnerable to deserialization of untrusted data. The library deserializes arbitrary attacker-supplied .NET classes, which can be abused to achieve remote code execution on the application server.

The product is no longer supported — CISA classifies it as end-of-life / end-of-service. There is no patch to apply. The only effective response is removing the library from the application or migrating to a supported AJAX call mechanism.

The combination of 89% EPSS and KEV status means this is not a theoretical risk: the vulnerability is being exploited at scale, and attacker scanners look for it deliberately.

Required Actions

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 “Prioritizing Security Updates Based on Risk” guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Because the library is unsupported, the order of operations differs from ordinary patching:

  1. Determine whether ajaxpro.2 (or AjaxPro.dll) appears in any maintained .NET application — including ones nobody actively develops.
  2. If so, cut off access to AjaxPro endpoints from untrusted networks before planning removal.
  3. Plan migration or decommissioning. There is no version to upgrade to.

CISA’s deadline for US federal agencies: 2026-09-09.

Who Is Affected?

The vulnerability affects ASP.NET applications using the Ajax.NET Professional (AjaxPro) library in any version.

This is a library from the early ASP.NET era — today found almost exclusively in legacy applications that still run because they carry a business process, but have no active development team. Such applications are genuinely present in finance, insurance and public administration, where internal systems live for a decade or more. It is worth checking the application inventory for the mere presence of AjaxPro.dll — the high EPSS score means the window for reacting is short.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist