CVE-2026-102454

EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • Published Sep 30, 2026
  • CVSS 8.6 high
  • 0.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-102454 at the National Vulnerability Database