// CVE

CVE-2021-23758

High 8.1 Exploited (KEV)

n/a AjaxPro.2

8.1CVSS
89%EPSS
YesCISA KEV

Summary

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

Published: 2021-12-03 · In KEV since: 2026-08-26

Analysis

🔴 Critical — actively exploited

Weakness: Insecure Deserialization (CWE-502). Untrusted serialized data leads to code execution.

How it's exploited: Exploitable over the network (internet-reachable), unauthenticated, no user interaction, with high complexity.

Impact: Full compromise (confidentiality, integrity and availability).

Status: Active exploitation confirmed by CISA (KEV).

How to defend:
  • Patch now: it is in CISA's actively-exploited catalog (KEV), with a deadline.
  • Reduce exposure: keep it off the internet; firewall, VPN or network segmentation.
  • Detect: turn this CVE into detection rules.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

The vector encodes how it's exploited (translated above, in the analysis). Break it down in the CVSS tool →

← Back to the Threat Radar

Sources: CISA KEV · EPSS · FIRST.org · NVD. Analysis derived from the CVSS vector and exploitation status (no AI). Informational; always verify against the vendor's official advisory.