---
id: CVE-2021-23758
title: >-
  All versions of package ajaxpro.2 are vulnerable to Deserialization of
  Untrusted Data due to the possibility of deserialization of arbitrary .NET
  classes, which can be abused to gain remote code execution.
summary: >-
  All versions of package ajaxpro.2 are vulnerable to Deserialization of
  Untrusted Data due to the possibility of deserialization of arbitrary .NET
  classes, which can be abused to gain remote code execution.
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
  - CWE-502
vendor: ajaxpro.2_project
product: ajaxpro.2
affected:
  - ajaxpro.2 < 21.10.30.1
patched:
  - ajaxpro.2 21.10.30.1
published: '2021-12-03'
updated: '2026-08-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-23758'
references:
  - url: >-
      http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
    label: report@snyk.io
  - url: >-
      https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971'
    label: report@snyk.io
  - url: >-
      http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.82578
epssPercentile: 0.99656
kev: true
kevDateAdded: '2026-08-26'
kevDueDate: '2026-09-09'
kevRansomware: false
exploited: true
ingestedAt: '2026-08-26T18:47:53.512Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/numanturle/CVE-2021-23758-POC'
  metasploit:
    - exploit/windows/http/ajaxpro_deserialization_rce
  checkedAt: '2026-09-26T09:05:26.356Z'
exploitAvailable: true
---

## Overview

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

## Affected

- `ajaxpro.2 < 21.10.30.1`

## Remediation

Upgrade past the affected range:

- `ajaxpro.2 21.10.30.1`
