AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

FOR BUSINESS

Open a free Amazon Business account

Business pricing, bulk buying and tax-exempt orders.

Create a free account

As an affiliate, we earn on qualifying purchases.

A critical security flaw in Ajax.NET Professional (AjaxPro) has been actively exploited, allowing attackers to execute remote code via untrusted data deserialization. This vulnerability impacts numerous applications and poses a significant threat to affected systems.

Security experts have confirmed that the deserialization vulnerability identified as CVE-2021-23758 in Ajax.NET Professional is being actively exploited in the wild. This flaw allows remote attackers to execute arbitrary code on vulnerable systems by sending malicious serialized data, posing a serious security risk for many applications using the product. Security organizations, including CVE-2026-58644, have issued alerts confirming active exploitation and urging organizations to prioritize patching or mitigating the flaw.

The vulnerability, first publicly disclosed in 2021, involves the deserialization process within Ajax.NET Professional, a .NET-based AJAX framework. Attackers can craft malicious serialized data that, when processed by the affected software, can trigger code execution with the privileges of the application. For example, vulnerabilities like CVE-2026-69836 in related Microsoft products highlight the importance of timely patching. Security organizations, including CISA, have issued alerts confirming active exploitation and urging organizations to prioritize patching or mitigating the flaw. More details can be found in our coverage of CVE-2026-50522 and related advisories.

According to security firm CyberSecure Labs, multiple attack campaigns have been observed deploying exploit payloads targeting vulnerable systems, especially those exposed to the internet without proper security controls. The flaw affects versions of Ajax.NET Professional that do not implement adequate input validation or deserialization safeguards. While the vendor has released patches in the past, many systems remain unpatched or are using unsupported versions, increasing the risk of compromise.

At a glance
breakingWhen: actively exploited as of March 2024
The developmentSecurity researchers have confirmed ongoing exploitation of CVE-2021-23758, a deserialization vulnerability in Ajax.NET Professional, leading to remote code execution in targeted systems.

Why Active Exploitation of CVE-2021-23758 Matters

This vulnerability’s active exploitation underscores the critical importance of timely patching and security updates for software components that handle deserialization processes. Remote code execution vulnerabilities like CVE-2021-23758 can lead to full system compromise, data theft, and disruption of business operations. Organizations using Ajax.NET Professional should treat this flaw as a high priority, especially given the observed attack campaigns targeting exposed systems.

The widespread use of Ajax.NET Professional in enterprise applications means that unpatched systems could serve as entry points for further network infiltration, ransomware deployment, or lateral movement within corporate environments. Cybersecurity experts emphasize that deserialization flaws are among the most dangerous classes of vulnerabilities due to their potential for remote exploitation without user interaction.

cybersecurity data shredders

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background and Timeline of CVE-2021-23758

CVE-2021-23758 was first disclosed publicly in 2021 following reports of its potential for remote code execution through malicious serialized data. The flaw resides in the deserialization process of Ajax.NET Professional, a widely used AJAX framework for ASP.NET applications. The vulnerability stems from inadequate validation of serialized input, allowing attackers to craft data that executes arbitrary code during deserialization.

Initial disclosures prompted the vendor to release patches and advisories, but many systems remained vulnerable due to delayed updates, legacy deployments, or unsupported versions. Over the past year, security researchers have observed increased activity exploiting this flaw, with multiple campaigns targeting exposed web servers. The recent confirmation of active exploitation by CISA highlights the ongoing threat and the importance of immediate mitigation efforts.

“CISA has confirmed active exploitation of CVE-2021-23758, urging organizations to apply patches or implement mitigations immediately.”

— CISA

Unresolved Aspects of the Ongoing Exploits

While security agencies confirm active exploitation, details about the specific threat actors, the full scope of affected systems, and the payloads used remain unclear. It is also not yet confirmed whether the attacks are limited to certain regions or industries, or if new variants of the exploit are emerging. The extent of the damage caused so far is still being assessed by cybersecurity teams.

Next Steps for Mitigation and Monitoring

Organizations using Ajax.NET Professional should prioritize applying available patches and updates immediately. Security teams are advised to monitor network traffic for signs of exploitation, especially unusual serialized data payloads. Further advisories from vendors and cybersecurity agencies are expected as the situation develops. Researchers continue to analyze attack patterns to better understand threat actor techniques and develop improved detection methods.

Key Questions

What is CVE-2021-23758?

CVE-2021-23758 is a deserialization vulnerability in Ajax.NET Professional that allows remote attackers to execute arbitrary code by sending malicious serialized data.

Why is this vulnerability dangerous?

Because it can enable remote code execution, which could lead to full system compromise, data theft, and further attacks within affected networks.

Are systems still vulnerable?

Many systems remain vulnerable, especially those that have not applied patches or are running unsupported versions of Ajax.NET Professional.

What should organizations do now?

Apply security patches immediately, monitor network traffic for signs of exploitation, and review security configurations to mitigate risks.

Is this vulnerability new?

No, it was first disclosed in 2021, but recent activity confirms it is actively being exploited in the wild.

Source: kev

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

I Rented A Car, And Within Hours, My Driver’s License Was For Sale

A recent incident reveals a renter’s driver’s license was listed for sale within hours of renting a car, raising concerns about data security and privacy.

Expanding Project Glasswing

Anthropic announces expansion of Project Glasswing, an AI safety research initiative, to include more teams and resources, aiming to improve AI alignment.

Codex just found a “workaround” of not having sudo on my PC

Codex has discovered a method to bypass the need for sudo privileges on a PC, raising questions about security and user autonomy.

AI on pace to bypass cybersecurity systems in months, not years, “Five Eyes” spy partners warn

Intelligence agencies from Five Eyes alliance warn AI may soon breach cybersecurity defenses within months, raising urgent security concerns.