<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>EasyFlow .NET - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/easyflow-.net/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 10:33:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/easyflow-.net/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Digiwin EasyFlow .NET via Insecure Deserialization</title><link>https://feed.craftedsignal.io/briefs/2026-09-easyflow-deserialization/</link><pubDate>Wed, 30 Sep 2026 10:33:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-easyflow-deserialization/</guid><description>Digiwin EasyFlow .NET is vulnerable to an insecure deserialization flaw, enabling unauthenticated remote attackers to achieve arbitrary code execution via crafted serialized input.</description><content:encoded><![CDATA[<p>Digiwin EasyFlow .NET contains a critical security vulnerability (CVE-2026-102455) arising from improper deserialization of untrusted data. An unauthenticated, remote attacker can exploit this flaw by sending a specially crafted serialized payload to the affected application. Successful exploitation results in remote code execution (RCE) with the privileges of the web service account. Given the nature of deserialization vulnerabilities in .NET applications, this typically occurs when the application uses insecure formatter settings or fails to validate object types during the deserialization process. This threat is particularly significant for enterprise environments using EasyFlow .NET for workflow management, as it provides a direct path for attackers to gain full control over the application server without prior authentication.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary code on the underlying host server. This can lead to full system compromise, exfiltration of sensitive organizational data, lateral movement within the network, or the deployment of additional malicious payloads such as ransomware. The high CVSS score of 9.8 reflects the ease of access and the severity of the potential impact on affected enterprise deployments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately isolate internet-facing EasyFlow .NET servers until patches are applied.</li>
<li>Monitor web server logs for HTTP requests containing large or obfuscated base64-encoded blobs, which are often indicative of serialized .NET object delivery.</li>
<li>Audit web server service accounts to ensure they operate with the principle of least privilege, limiting the potential impact of successful RCE.</li>
<li>Engage with the Digiwin vendor support channel to obtain and apply the specific security update addressing CVE-2026-102455.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>deserialization</category><category>web-application</category><category>vulnerability</category><category>rce</category></item></channel></rss>