Kiteworks patches max severity code injection vulnerability
Kiteworks has patched a maximum-severity code injection vulnerability in its Email Protection Gateway (EPG) component, part of the Kiteworks Private Content Network. The flaw allowed unauthenticated remote attackers to execute arbitrary code and escalate to full administrative control via a chain of path traversal, code injection, and missing authentication issues. The vulnerability affects all EPG versions before 9.4.1 and has been fixed in version 9.4.1. Kiteworks also addressed 125 other vulnerabilities, including critical authentication bypass and access control flaws. The company urged customers to shut down servers temporarily due to threat intelligence warnings but found no evidence of compromise after patching. No CVE ID was initially assigned, but the vulnerability is tracked as CVE-2026-54154.
AI Analysis
Technical Summary
Kiteworks released security updates addressing 126 vulnerabilities, including a maximum-severity code injection vulnerability (CVE-2026-54154) in the Email Protection Gateway (EPG). This flaw allowed unauthenticated remote attackers to achieve arbitrary code execution and escalate privileges to root by exploiting a combination of input-handling flaws involving path traversal, code injection, and missing authentication. The vulnerability affects all EPG versions prior to 9.4.1 and is patched in 9.4.1 and later. Kiteworks also fixed multiple critical vulnerabilities in core components. The company temporarily advised customers to shut down servers due to a potential zero-day attack but lifted the advisory after patching and found no signs of compromise. The vulnerability was reported through Kiteworks' bug bounty program on YesWeHack.
Potential Impact
Successful exploitation enables unauthenticated remote attackers to execute arbitrary code and gain full administrative (root) control over the Kiteworks Email Protection Gateway appliance. This could lead to complete takeover of the affected system. The vulnerability affects all versions before 9.4.1. Kiteworks found no evidence of active exploitation or compromise prior to patching.
Mitigation Recommendations
Kiteworks has released an official patch in version 9.4.1 that fixes this vulnerability. Customers should upgrade their Email Protection Gateway to version 9.4.1 or later. Kiteworks previously recommended temporarily shutting down affected servers as a precaution but has since lifted this advisory after patching. No additional mitigation steps are required beyond applying the official update.
Kiteworks patches max severity code injection vulnerability
Description
Kiteworks has patched a maximum-severity code injection vulnerability in its Email Protection Gateway (EPG) component, part of the Kiteworks Private Content Network. The flaw allowed unauthenticated remote attackers to execute arbitrary code and escalate to full administrative control via a chain of path traversal, code injection, and missing authentication issues. The vulnerability affects all EPG versions before 9.4.1 and has been fixed in version 9.4.1. Kiteworks also addressed 125 other vulnerabilities, including critical authentication bypass and access control flaws. The company urged customers to shut down servers temporarily due to threat intelligence warnings but found no evidence of compromise after patching. No CVE ID was initially assigned, but the vulnerability is tracked as CVE-2026-54154.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kiteworks released security updates addressing 126 vulnerabilities, including a maximum-severity code injection vulnerability (CVE-2026-54154) in the Email Protection Gateway (EPG). This flaw allowed unauthenticated remote attackers to achieve arbitrary code execution and escalate privileges to root by exploiting a combination of input-handling flaws involving path traversal, code injection, and missing authentication. The vulnerability affects all EPG versions prior to 9.4.1 and is patched in 9.4.1 and later. Kiteworks also fixed multiple critical vulnerabilities in core components. The company temporarily advised customers to shut down servers due to a potential zero-day attack but lifted the advisory after patching and found no signs of compromise. The vulnerability was reported through Kiteworks' bug bounty program on YesWeHack.
Potential Impact
Successful exploitation enables unauthenticated remote attackers to execute arbitrary code and gain full administrative (root) control over the Kiteworks Email Protection Gateway appliance. This could lead to complete takeover of the affected system. The vulnerability affects all versions before 9.4.1. Kiteworks found no evidence of active exploitation or compromise prior to patching.
Mitigation Recommendations
Kiteworks has released an official patch in version 9.4.1 that fixes this vulnerability. Customers should upgrade their Email Protection Gateway to version 9.4.1 or later. Kiteworks previously recommended temporarily shutting down affected servers as a precaution but has since lifted this advisory after patching. No additional mitigation steps are required beyond applying the official update.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/","fetched":true,"fetchedAt":"2026-10-01T14:44:31.909Z","wordCount":677}
Threat ID: 6abe71d1b45efb4220454420
Added to database: 10/01/2026, 14:44:33 UTC
Last enriched: 10/01/2026, 14:44:55 UTC
Last updated: 10/01/2026, 14:46:41 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.