CVE-2021-23758 carries a CVSS 3.1 base score of 8.1 against Ajax.NET Professional (package name ajaxpro.2), a .NET AJAX framework. NVD classifies it as CWE-502 (Deserialization of Untrusted Data). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 26, 2026 — confirming exploitation directly through CISA’s own listing process, nearly five years after this vulnerability was originally disclosed in December 2021.
Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.
What the flaw is
NVD’s description states that all versions of the ajaxpro.2 package are vulnerable to deserialization of untrusted data, due to the possibility of deserializing arbitrary .NET classes, which can be abused to gain remote code execution. NVD’s record does not carry a fixed-version field; the fix, per a linked GitHub commit, predates NVD’s current record but our source data does not carry the specific version that first included it.
Evidence and confidence
- High confidence — exploitation status, sourced directly from CISA KEV, which our evidence model treats as an authoritative single source for this specific field.
- Medium confidence — the CVSS 8.1 score, the vector (
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), and the CWE-502 classification, which trace to NVD alone in our current ingestion. - Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.83633, a 99.7th percentile score as of our ingestion — among the highest in our recent KEV coverage.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field; consult the linked vendor fix commit or your Ajax.NET Professional distribution directly for patch guidance.
Why this matters
A 2021-disclosed vulnerability appearing on CISA’s KEV catalog in 2026 typically reflects newly observed exploitation of deployments that were never patched in the intervening years, a pattern this publication has covered before with other long-unpatched software (including, this cycle, a similarly aged Microsoft SQL Server flaw). Ajax.NET Professional is a legacy .NET component that may be embedded inside larger applications rather than tracked as a standalone dependency, which can leave it unpatched long after a fix becomes available even in organizations with otherwise disciplined patch management.
The near-maximal EPSS percentile (99.7th) combined with CISA’s direct confirmation of exploitation makes clear this is an actively exploited flaw today, not a dormant historical entry, and any organization with this package present in its .NET application stack should prioritize identifying and remediating it.
Frequently Asked Questions
What is CVE-2021-23758?
A CVSS 8.1 deserialization of untrusted data vulnerability (CWE-502) affecting all versions of the ajaxpro.2 package (Ajax.NET Professional), allowing remote code execution via deserialization of arbitrary .NET classes.
Is CVE-2021-23758 being actively exploited? Yes, per CISA’s own Known Exploited Vulnerabilities catalog, which added this CVE on August 26, 2026.
Why is a 2021 CVE showing up in a 2026 KEV feed? CISA added it to its Known Exploited Vulnerabilities catalog in August 2026 — nearly five years after initial disclosure — which typically reflects newly observed exploitation of deployments that were never patched, not a new vulnerability.
Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.
Which version fixes this? Our source data does not carry a specific fixed-version field. Consult the linked fix commit on GitHub or your distribution’s own changelog for the version that resolves this issue.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2021-23758. Exploitation status and the August 26, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry. Fix reference: GitHub commit. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.