MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-01 · via BleepingComputer

Kiteworks Fixes Critical Code Injection Flaw in Email Security Gateway

Image via BleepingComputer
Image via BleepingComputer

Kiteworks released patches for 126 vulnerabilities in its secure file-sharing platform, with a maximum-severity code injection flaw in its Email Protection Gateway allowing unauthenticated attackers to gain remote code execution and full administrative control. The vulnerability, tracked as CVE-2026-54154, affected all EPG releases before version 9.4.1 and was discovered through a bug bounty program. This follows the company's precautionary server shutdown last week due to threat intelligence warnings of potential zero-day attacks.

Expanded Detail

Kiteworks addressed a sweeping batch of security defects affecting its unified content network platform, which serves major corporations and government organizations worldwide. The vulnerability chain in the Email Protection Gateway component enabled attackers to bypass authentication requirements and inject malicious code through exposed network interfaces, ultimately granting them system-level administrative access without requiring any legitimate credentials or user participation in the attack.

This disclosure follows the company's recent precautionary measure to take customer infrastructure offline after receiving advance warning of potential zero-day exploitation. The swift identification and patching of CVE-2026-54154 through responsible disclosure channels allowed Kiteworks to restore service within days while asserting that no actual breaches or malicious activity had occurred during the temporary shutdown period.

Context

Organizations relying on Kiteworks for secure communications and file transfer may face operational risks if systems remain unpatched, particularly given the vulnerability's low complexity and lack of authentication barriers. The incident could affect hundreds of thousands of end-users whose sensitive data flows through affected gateways. Prompt patching and verification of patch deployment may be critical to preventing potential unauthorized access to enterprise communications and protected documents. The approximately 400 exposed instances identified online underscore the importance of inventory management and update verification across internet-facing security infrastructure.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Cisco Releases Patches for Actively Exploited Network Management Platform Vulnerability · Cybersecurity
Critical Cisco Network Appliance Flaw Now Listed as Actively Exploited Vulnerability · Cybersecurity
Cisco SD-WAN Manager Zero-Day Allows Admin-Level API Access Without Credentials · Cybersecurity
Critical Zimbra Vulnerability Allows Unauthorized Remote Code Execution and Data Theft · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Kiteworks patches max severity code injection vulnerability.” Browse more stories.