<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:michaelschwarz:ajax.net_professional:*:*:*:*:*:.net:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amichaelschwarzajax.net_professional.net/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 26 Aug 2026 23:09:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amichaelschwarzajax.net_professional.net/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2021-23758 - Ajax.NET Professional Deserialization Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-ajaxnet-deserialization/</link><pubDate>Wed, 26 Aug 2026 23:09:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ajaxnet-deserialization/</guid><description>Ajax.NET Professional contains a deserialization of untrusted data vulnerability (CVE-2021-23758) that could allow remote attackers to achieve code execution through malicious .NET class payloads.</description><content:encoded><![CDATA[<p>Ajax.NET Professional (AjaxPro), an open-source library used to integrate AJAX functionality into .NET applications, is vulnerable to a deserialization of untrusted data flaw identified as CVE-2021-23758. An attacker can exploit this vulnerability by sending crafted input that triggers the deserialization of arbitrary .NET classes, potentially leading to remote code execution (RCE) on the host server. The component is currently considered end-of-life and end-of-service, leaving it without official security maintenance. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog and mandates that organizations prioritize patching or discontinue use of the component as per BOD 26-04 guidelines. Given the nature of the library as a third-party dependency, it may be embedded within various proprietary and legacy applications, making discovery and inventory critical for defense.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote, unauthenticated attackers to execute arbitrary code within the context of the application server. This could lead to full system compromise, data exfiltration, or lateral movement within the network. Because the library is often used as a hidden dependency in older web applications, the total number of exposed instances across critical sectors is unknown but poses a significant risk to legacy infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Conduct an immediate inventory of all applications within the environment to identify the presence of the Ajax.NET Professional library.</li>
<li>As the component is EoL/EoS, discontinue use of the library and migrate to supported alternatives immediately.</li>
<li>If immediate removal is not possible, implement strict network ingress filtering to block access to application paths utilizing AjaxPro until the application can be decommissioned or the dependency removed.</li>
<li>Ensure compliance with CISA BOD 26-04 by evaluating internet-exposed assets for the presence of this vulnerability and implementing compensating controls where patching is not possible.</li>
<li>Review web server access logs for anomalous POST requests directed at application endpoints that rely on AjaxPro, as this is the primary vector for delivering the malicious payload.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>