Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Ajax.NET Professional Software

A serious security weakness has been found in Ajax.NET Professional software that could allow hackers to take control of affected systems remotely. This vulnerability is actively being exploited, so it is important for organisations using this software to act quickly to reduce risk.

28 August 2026

Reference: CVE-2021-23758

1. What is being reported?

The vulnerability involves a problem with how Ajax.NET Professional handles certain data, allowing attackers to run harmful code on a computer without permission. This happens because the software can mistakenly trust unsafe data, leading to a security breach.

2. What this means in plain English

If your organisation uses Ajax.NET Professional, attackers might be able to break into your systems and cause damage or steal information. This risk is serious because it can happen remotely and without warning.

3. Could this affect a small business?

Small businesses or organisations using Ajax.NET Professional software could be affected, especially if the software is connected to the internet. If you do not use this software, or it is not internet-facing, you are likely not at risk.

4. What to do now

  • Check if your organisation uses Ajax.NET Professional software.
  • Contact your IT provider or software supplier to confirm if you are using a vulnerable version.
  • Apply any security updates or mitigations recommended by the software vendor immediately.
  • If no fix is available, consider discontinuing use of the software or isolating it from internet access.

5. Ask your IT provider

Can you confirm whether our systems use Ajax.NET Professional, and if so, have all recommended security updates or mitigations for CVE-2021-23758 been applied?

6. Bottom line

If you use Ajax.NET Professional, act now to secure your systems against a known and actively exploited vulnerability.

Information based on CISA KEV, NVD, and reputable security reporting.

Back to Vulnerability Briefs