Mmastodon TechnologyCybersecurity first seen 10 h ago, last 10 h ago, peak #4
Critical flaw in Digiwin EasyFlow .NET exposes plaintext passwords
Original: 🚨 CVE-2026-102458 — CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Una
A critical vulnerability, CVE-2026-102458 with a CVSS score of 9.3, has been disclosed in EasyFlow .NET, enterprise software developed by Taiwanese vendor Digiwin. The flaw is a missing authentication issue: unauthenticated remote attackers can use a specific API to obtain other users' plaintext passwords. Security watchers are sharing details and urging affected organisations to review exposure and patch quickly.
Why now: A newly disclosed critical vulnerability allowing password theft is a pressing concern for organisations running the affected software.
DigiwinEasyFlow .NETCVE-2026-102458
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/470710