OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102455

CRITICAL · CVSS 9.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The EasyFlow .NET application by Digiwin is vulnerable to an insecure deserialization flaw that allows unauthenticated remote attackers to execute arbitrary code on the server through specially crafted serialized data. This critical vulnerability, rated with a CVSS score of 9.8, poses a significant risk to any organization using this software. Organizations utilizing EasyFlow .NET should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-102455
Severity
CRITICAL
CVSS
9.8
EPSS
0.51%

Original NVD Description

EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.