CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Published Dec 3, 2021
·
Updated

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Other sources

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Affected Software

5 affected componentsFixes available
nuget/AjaxNetProfessional<=21.11.29
21.11.29.1
Ajaxpro.2 Project Ajaxpro.2 .net<21.10.30.1
Ajaxpro.2 Project Ajaxpro.2 .net
Michaelschwarz Ajax.net Professional .net<21.10.30.1
Ajax.NET Professional Ajax.NET Professional

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nuget/AjaxNetProfessional to a version that resolves this vulnerability.

    Fixed in 21.11.29.1

Event History

Dec 3, 2021
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 16, 2021
Advisory Published
03:27 PM
Aug 26, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

Which deployments are affected?

All versions of the ajaxpro.2 package are vulnerable. The affected software identifiers include Ajax.NET Professional/AjaxPro and the NuGet package AjaxNetProfessional.

2

What does an attacker need to exploit this issue?

The CVSS vector indicates exploitation can be performed remotely with low attack complexity, no privileges, and no user interaction. The issue arises from deserialization of arbitrary .NET classes and can lead to remote code execution.

3

Is this vulnerability being exploited?

Yes. It is flagged as exploited and was added to the KEV list on 2026-08-26.

4

What should teams do if they use Ajax.NET Professional?

Users are advised to discontinue use or transition to a supported version, as impacted products may be end-of-life or end-of-service. The provided data states that all ajaxpro.2 versions are vulnerable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203