High severity8.1CISA KEVNVD Advisory· Published Dec 3, 2021· Updated Aug 27, 2026
CVE-2021-23758
CVE-2021-23758
Description
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
AjaxNetProfessionalNuGet | < 21.11.29.1 | 21.11.29.1 |
Affected products
3- cpe:2.3:a:ajaxpro.2_project:ajaxpro.2:*:*:*:*:*:.net:*:*Range: <21.10.30.1
- ajaxpro.2/ajaxpro.2description
Patches
Vulnerability mechanics
References
9- github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57nvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.htmlnvdExploitVDB EntryWEB
- blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-6r7c-6w96-8pvwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23758ghsaADVISORY
- snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971nvdThird Party Advisory
- github.com/michaelschwarz/Ajax.NET-Professional/security/advisories/GHSA-6r7c-6w96-8pvwghsaWEB
- security.snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971ghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
6- CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix ProductsInfosecurity Magazine · Aug 27, 2026
- Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)Help Net Security · Aug 27, 2026
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server BugsThe Hacker News · Aug 27, 2026
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux RootkitThe Hacker News · Aug 24, 2026
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsCisco Talos Intelligence · Aug 20, 2026
- CISA Adds Six Known Exploited Vulnerabilities to CatalogCISA Alerts