{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aajaxpro.2_projectajaxpro.2.net/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ajaxpro.2_project:ajaxpro.2:*:*:*:*:*:.net:*:*","cpe:2.3:a:michaelschwarz:ajax.net_professional:*:*:*:*:*:.net:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2021-23758"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ajax.NET Professional"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eAjax.NET Professional (AjaxPro), an open-source library used to integrate AJAX functionality into .NET applications, is vulnerable to a deserialization of untrusted data flaw identified as CVE-2021-23758. An attacker can exploit this vulnerability by sending crafted input that triggers the deserialization of arbitrary .NET classes, potentially leading to remote code execution (RCE) on the host server. The component is currently considered end-of-life and end-of-service, leaving it without official security maintenance. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog and mandates that organizations prioritize patching or discontinue use of the component as per BOD 26-04 guidelines. Given the nature of the library as a third-party dependency, it may be embedded within various proprietary and legacy applications, making discovery and inventory critical for defense.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to execute arbitrary code within the context of the application server. This could lead to full system compromise, data exfiltration, or lateral movement within the network. Because the library is often used as a hidden dependency in older web applications, the total number of exposed instances across critical sectors is unknown but poses a significant risk to legacy infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConduct an immediate inventory of all applications within the environment to identify the presence of the Ajax.NET Professional library.\u003c/li\u003e\n\u003cli\u003eAs the component is EoL/EoS, discontinue use of the library and migrate to supported alternatives immediately.\u003c/li\u003e\n\u003cli\u003eIf immediate removal is not possible, implement strict network ingress filtering to block access to application paths utilizing AjaxPro until the application can be decommissioned or the dependency removed.\u003c/li\u003e\n\u003cli\u003eEnsure compliance with CISA BOD 26-04 by evaluating internet-exposed assets for the presence of this vulnerability and implementing compensating controls where patching is not possible.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests directed at application endpoints that rely on AjaxPro, as this is the primary vector for delivering the malicious payload.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T23:09:49Z","date_published":"2026-08-26T23:09:49Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ajaxnet-deserialization/","summary":"Ajax.NET Professional contains a deserialization of untrusted data vulnerability (CVE-2021-23758) that could allow remote attackers to achieve code execution through malicious .NET class payloads.","title":"CVE-2021-23758 - Ajax.NET Professional Deserialization Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-ajaxnet-deserialization/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ajaxpro.2_project:ajaxpro.2:*:*:*:*:*:.net:*:*","version":"https://jsonfeed.org/version/1.1"}