Skip to main content

Kiteworks patches max severity code injection vulnerability

0
Critical
Vulnerability
Published: 10/01/2026 (10/01/2026, 13:51:08 UTC)
Source: Bleeping Computer

Description

Kiteworks has patched a maximum-severity code injection vulnerability in its Email Protection Gateway (EPG) component, part of the Kiteworks Private Content Network. The flaw allowed unauthenticated remote attackers to execute arbitrary code and escalate to full administrative control via a chain of path traversal, code injection, and missing authentication issues. The vulnerability affects all EPG versions before 9.4.1 and has been fixed in version 9.4.1. Kiteworks also addressed 125 other vulnerabilities, including critical authentication bypass and access control flaws. The company urged customers to shut down servers temporarily due to threat intelligence warnings but found no evidence of compromise after patching. No CVE ID was initially assigned, but the vulnerability is tracked as CVE-2026-54154.

Affected software

Affected versions
<9.4.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 14:44:55 UTC

Technical Analysis

Kiteworks released security updates addressing 126 vulnerabilities, including a maximum-severity code injection vulnerability (CVE-2026-54154) in the Email Protection Gateway (EPG). This flaw allowed unauthenticated remote attackers to achieve arbitrary code execution and escalate privileges to root by exploiting a combination of input-handling flaws involving path traversal, code injection, and missing authentication. The vulnerability affects all EPG versions prior to 9.4.1 and is patched in 9.4.1 and later. Kiteworks also fixed multiple critical vulnerabilities in core components. The company temporarily advised customers to shut down servers due to a potential zero-day attack but lifted the advisory after patching and found no signs of compromise. The vulnerability was reported through Kiteworks' bug bounty program on YesWeHack.

Potential Impact

Successful exploitation enables unauthenticated remote attackers to execute arbitrary code and gain full administrative (root) control over the Kiteworks Email Protection Gateway appliance. This could lead to complete takeover of the affected system. The vulnerability affects all versions before 9.4.1. Kiteworks found no evidence of active exploitation or compromise prior to patching.

Mitigation Recommendations

Kiteworks has released an official patch in version 9.4.1 that fixes this vulnerability. Customers should upgrade their Email Protection Gateway to version 9.4.1 or later. Kiteworks previously recommended temporarily shutting down affected servers as a precaution but has since lifted this advisory after patching. No additional mitigation steps are required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/","fetched":true,"fetchedAt":"2026-10-01T14:44:31.909Z","wordCount":677}

Threat ID: 6abe71d1b45efb4220454420

Added to database: 10/01/2026, 14:44:33 UTC

Last enriched: 10/01/2026, 14:44:55 UTC

Last updated: 10/01/2026, 14:46:41 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses