Cyber & AI intelligence
Wasteland.
Briefs indexed2945
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102455 2026-09-30

Critical Unauthenticated RCE in Digiwin EasyFlow .NET (CVE-2026-102455)

"CVE-2026-102455 is a critical insecure deserialization flaw in Digiwin's EasyFlow .NET that lets unauthenticated remote attackers run arbitrary code on the server."

CVE-2026-102455 is a critical insecure deserialization flaw in Digiwin's EasyFlow .NET that lets unauthenticated remote attackers run arbitrary code on the server.

What Is It

TWCERT/CC reported CVE-2026-102455, an insecure deserialization vulnerability (CWE-502) in EasyFlow .NET, developed by Digiwin. According to the NVD description, unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

The record was published to NVD on 2026-09-30 and has the status "Received." That means NVD has not yet completed its own analysis.

Why It Matters

TWCERT/CC, the CNA, rated the flaw 9.8 CRITICAL under CVSS 3.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. The vector shows why:

A successful attack gives the attacker code execution on the server hosting EasyFlow .NET.

Exploitation status: CVE-2026-102455 is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the supplied data does not confirm active exploitation. The CVSS 4.0 exploit maturity field is "Not Defined."

What's Vulnerable

The CNA lists these versions of DigiWin EasyFlow .NET as affected:

Version branch Affected range
6.1 All 6.1.* versions
6.6 6.6 through 6.6.19
8.1 8.1 through 8.1.5

Versions outside these ranges are listed as unaffected by default. The NVD record does not yet include CPE entries.

Patch Status

The NVD record does not name a fixed version or give remediation steps, and there is no CISA KEV entry, so no federal remediation deadline applies. Organizations running an affected EasyFlow .NET branch should:

Sources