Kiteworks has released security updates addressing 126 vulnerabilities, including a maximum-severity flaw in its Email Protection Gateway (EPG). The EPG is part of the company’s Private Content Network (PCN), which combines enterprise email, Managed File Transfer (MFT), file sharing, APIs and web forms.
Tracked as CVE-2026-54154, the flaw could let an unauthenticated remote attacker execute code and take control of a targeted EPG appliance. The reported attack chain combines path traversal, code injection and missing authentication, and does not require user interaction. Kiteworks said the issue was reported through its bug bounty program on YesWeHack.
The vulnerability affects EPG releases before 9.4.1. Kiteworks says it is fixed in version 9.4.1 and later. The company also fixed 11 critical vulnerabilities in its Core and EPG components, involving authentication bypass, administrator account takeover, stored cross-site scripting (XSS), improper access control and improper authentication.
In a Wednesday advisory, Kiteworks said flaws in input handling at publicly reachable endpoints could allow arbitrary code execution and, when combined with other local weaknesses, escalation to root control.
Last week, the company advised customers to shut down their servers after receiving threat intelligence about a potentially imminent zero-day attack. It lifted that precaution on Monday after patching a critical vulnerability and restoring hosted customer systems. Kiteworks said it found no evidence of compromise or suspicious activity. It has not shared further details about that earlier vulnerability or assigned it a CVE identifier.
Shadowserver tracks nearly 400 Kiteworks instances exposed to the internet, but has not said how many are patched or are honeypots.
Comments
0No comments yet. Be the first to comment.