[KEV] CVE-2021-23758 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2021-23758 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2021-23758 is an unsafe deserialization vulnerability in Ajax.NET Professional (AjaxPro) that can expose applications using the framework to remote code execution through attacker-controlled serialized .NET data.
Technical Detail
AjaxPro deserializes untrusted input in a manner that may allow an attacker to instantiate arbitrary .NET classes. An attacker who can submit crafted data to a vulnerable AjaxPro application may trigger execution of code on the affected server. Successful exploitation can result in remote code execution in the security context of the application process.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation tooling or techniques are sufficiently developed for practical use by attackers. CISA has confirmed active exploitation in the wild and added this vulnerability to the Known Exploited Vulnerabilities Catalog on August 26, 2026.
Who Is Targeting This
Reported (research-inferred): No public attribution to a named MITRE ATT&CK group or ransomware operation has been identified. Tooling such as Meterpreter and Spectre RAT has been observed, but the activity has not been mapped to a specific MITRE ATT&CK intrusion set. No confirmed threat actor attribution is available at this time.
What To Do
Treat internet-accessible AjaxPro deployments as urgent remediation targets. Ajax.NET Professional may be end-of-life or end-of-service; discontinue its use or migrate affected applications to a supported alternative where possible. If continued use is unavoidable, remove public access to affected application functions, restrict access to trusted networks and authenticated users, and apply available vendor or application-level mitigations that prevent untrusted data from reaching AjaxPro deserialization routines. CISA added the vulnerability to the KEV Catalog on August 26, 2026; patch by the applicable CISA Binding Operational Directive deadline or apply mitigations. Monitor affected servers for anomalous application requests, unexpected .NET application errors, suspicious child processes spawned by web application worker processes, and outbound connections originating from the application server.