CVE-2026-102455 is a critical insecure deserialization flaw in Digiwin's EasyFlow .NET that lets unauthenticated remote attackers run arbitrary code on the server.
What Is It
TWCERT/CC reported CVE-2026-102455, an insecure deserialization vulnerability (CWE-502) in EasyFlow .NET, developed by Digiwin. According to the NVD description, unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
The record was published to NVD on 2026-09-30 and has the status "Received." That means NVD has not yet completed its own analysis.
Why It Matters
TWCERT/CC, the CNA, rated the flaw 9.8 CRITICAL under CVSS 3.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and 9.3 CRITICAL under CVSS 4.0. The vector shows why:
- Network-reachable: it can be exploited remotely.
- Low complexity: no special conditions are needed.
- No authentication or user interaction required.
- High impact on confidentiality, integrity and availability of the affected server.
A successful attack gives the attacker code execution on the server hosting EasyFlow .NET.
Exploitation status: CVE-2026-102455 is not in the CISA Known Exploited Vulnerabilities (KEV) catalog, and the supplied data does not confirm active exploitation. The CVSS 4.0 exploit maturity field is "Not Defined."
What's Vulnerable
The CNA lists these versions of DigiWin EasyFlow .NET as affected:
| Version branch | Affected range |
|---|---|
| 6.1 | All 6.1.* versions |
| 6.6 | 6.6 through 6.6.19 |
| 8.1 | 8.1 through 8.1.5 |
Versions outside these ranges are listed as unaffected by default. The NVD record does not yet include CPE entries.
Patch Status
The NVD record does not name a fixed version or give remediation steps, and there is no CISA KEV entry, so no federal remediation deadline applies. Organizations running an affected EasyFlow .NET branch should:
- Check the TWCERT/CC advisories below for vendor-supplied fix and upgrade guidance.
- Because the flaw needs no authentication, treat any internet-facing EasyFlow .NET instance on an affected version as a priority for remediation.