


Perceptive Security
SOC/SIEM Consultancy

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes…
Published:
26 augustus 2026 om 02:00:00
Alert date:
26 augustus 2026 om 20:02:55
Source:
cisa.gov

Web Technologies, Supply Chain & Dependencies, Zero-Day Vulnerabilities
CVE-2021-23758 affects Ajax.NET Professional (AjaxPro), an open-source .NET library, which contains a deserialization of untrusted data vulnerability. This flaw allows attackers to exploit arbitrary .NET class deserialization, potentially leading to remote code execution. The vulnerability is catalogued in CISA's Known Exploited Vulnerabilities catalog under BOD 26-04. The affected product may be end-of-life or end-of-service, and users are advised to discontinue use or migrate to a supported alternative. A patch commit is available on GitHub for reference. The issue stems from improper handling of untrusted data during deserialization, a common and critical vulnerability class in web frameworks. Organizations using AjaxPro in their web applications are at risk of full system compromise if exploited. CISA has flagged this for prioritized remediation under its binding operational directive.
Technical details
Mitigation steps:
Affected products:
Ajax.NET Professional (AjaxPro)
Related links:
https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
https://nvd.nist.gov/vuln/detail/CVE-2021-23758
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.