๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Summary
Ajax.NET Professional contains a deserialization of untrusted data vulnerability (a flaw where the software unsafely processes data from untrusted sources, potentially allowing attackers to run malicious code) that could enable remote code execution (RCE, where an attacker runs commands on a system they don't own) through arbitrary .NET classes. The affected product may be end-of-life, and this vulnerability is currently being exploited by attackers in the wild.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions following CISA's BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. For cloud services, follow BOD 26-04 patching guidelines. See the vendor's GitHub commit for technical details: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
Vulnerability Details
EPSS: 89.1%
Yes
๐ฅ Actively Exploited
August 25, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-23758
First tracked: August 26, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%