{"ok":true,"trend":{"id":470710,"platform":"mastodon","region":"global","key":"🚨 cve-2026-102458 — cvss 9.3 critical easyflow .net developed by digiwin has a missing authentication vulnerability. una","title":"🚨 CVE-2026-102458 — CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Una","url":"https://mastodon.social/@stemshop/117359434108141100","first_seen":"2026-09-30T10:09:48.112702Z","last_seen":"2026-09-30T10:09:48.112702Z","last_rank":4,"peak_rank":4,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.502734375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical vulnerability, CVE-2026-102458 with a CVSS score of 9.3, has been disclosed in EasyFlow .NET, enterprise software developed by Taiwanese vendor Digiwin. The flaw is a missing authentication issue: unauthenticated remote attackers can use a specific API to obtain other users' plaintext passwords. Security watchers are sharing details and urging affected organisations to review exposure and patch quickly.","why":"A newly disclosed critical vulnerability allowing password theft is a pressing concern for organisations running the affected software.","tone":"neutral","entities":["Digiwin","EasyFlow .NET","CVE-2026-102458"],"summarized_at":"2026-09-30T10:09:59.496561Z","meta":{"tag":"cybersecurity","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1481},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical flaw in Digiwin EasyFlow .NET exposes plaintext passwords","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T10:09:48.112702Z","rank":4,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117359434108141100","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-102458 — CVSS 9.3 CRITICAL EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API. 🔎 Details: https:// stemshop.top/cve/CVE-2026-1024 58 # CVE…","posted_at":"2026-09-30T10:07:29.554000Z","likes":0}],"elsewhere":[],"window":"7d"}}