Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2021-23758 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2021-23758 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2021-23758 is an unsafe deserialization vulnerability in Ajax.NET Professional (AjaxPro) that can expose applications using the framework to remote code execution through attacker-controlled serialized .NET data.

Technical Detail

AjaxPro deserializes untrusted input in a manner that may allow an attacker to instantiate arbitrary .NET classes. An attacker who can submit crafted data to a vulnerable AjaxPro application may trigger execution of code on the affected server. Successful exploitation can result in remote code execution in the security context of the application process.

Exploitation Status

Exploit maturity is assessed as Operational, meaning exploitation tooling or techniques are sufficiently developed for practical use by attackers. CISA has confirmed active exploitation in the wild and added this vulnerability to the Known Exploited Vulnerabilities Catalog on August 26, 2026.

Who Is Targeting This

Reported (research-inferred): No public attribution to a named MITRE ATT&CK group or ransomware operation has been identified. Tooling such as Meterpreter and Spectre RAT has been observed, but the activity has not been mapped to a specific MITRE ATT&CK intrusion set. No confirmed threat actor attribution is available at this time.

What To Do

Treat internet-accessible AjaxPro deployments as urgent remediation targets. Ajax.NET Professional may be end-of-life or end-of-service; discontinue its use or migrate affected applications to a supported alternative where possible. If continued use is unavoidable, remove public access to affected application functions, restrict access to trusted networks and authenticated users, and apply available vendor or application-level mitigations that prevent untrusted data from reaching AjaxPro deserialization routines. CISA added the vulnerability to the KEV Catalog on August 26, 2026; patch by the applicable CISA Binding Operational Directive deadline or apply mitigations. Monitor affected servers for anomalous application requests, unexpected .NET application errors, suspicious child processes spawned by web application worker processes, and outbound connections originating from the application server.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →