CVE-2021-23758
Executive Summary
CVE‑2021‑23758 affects all versions of AjaxPro.2, enabling attackers to deserialize arbitrary .NET objects and achieve remote code execution. The vulnerability is actively exploited in the wild, as flagged by CISA’s KEV list. Immediate patching or mitigation is required for exposed ASP.NET applications.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2021-12-03T20:15:07.557 - Last Modified: 2026-08-27T04:16:38.863
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-08-26)
Original Description: All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
"Better than a thousand hollow words, is one word that brings peace."
— Buddha