Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to make crafted requests to internal or unintended network destinations when rendering message content with external resource references. Exploitation could lead to disclosure of sensitive internal information or unintended actions on internal systems. The vulnerability has a high severity with a CVSS score of 9.1. No explicit patch information is provided, so users should verify vendor advisories for remediation status. Join the discussion | CVE Database V5 | 09/30/2026, 20:25:02 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-102106 is an improper authentication vulnerability in the Kiteworks Email Protection Gateway administrative service. The service does not consistently enforce administrator authentication, allowing an attacker referencing a valid administrator account to bypass password checks. This can enable unauthorized creation, modification, or deletion of internal users and managed domains, as well as changes to security configurations. Deleting a managed domain can remove its user accounts and potentially lock out legitimate administrators. Join the discussion | CVE Database V5 | 09/30/2026, 20:24:46 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-102108 is a high-severity vulnerability in Kiteworks Email Protection Gateway that allows an authenticated administrator with specific queue-management privileges to submit crafted serialized objects to a cluster management interface. These objects are deserialized without sufficient validation, potentially enabling arbitrary code execution under the gateway service account. The vulnerability affects versions prior to 9.5.0. Join the discussion | CVE Database V5 | 09/30/2026, 20:24:07 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-102116 is a path traversal vulnerability in Kiteworks Email Protection Gateway that allows an authenticated administrator to write files outside intended directories. This flaw can lead to remote code execution by causing the application to execute malicious files written by the attacker. The vulnerability affects versions prior to 9.5.0. It has a high severity score of 7.2 and requires high privileges to exploit. Join the discussion | CVE Database V5 | 09/30/2026, 20:19:20 UTC Added: 09/30/2026, 20:34:21 UTC |
0 CVE-2026-102119 is a path traversal vulnerability in the Kiteworks Email Protection Gateway. It affects an optional, non-default administrative feature that allows an authenticated administrator to move files outside the intended directory. This could enable arbitrary code execution on the underlying system. The vulnerability affects versions prior to 9.5.0. The CVSS score is 7.2, indicating high severity. Join the discussion | CVE Database V5 | 09/30/2026, 20:18:01 UTC Added: 09/30/2026, 20:34:21 UTC |
0 Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to send crafted requests to internal or unintended network destinations during online certificate status checks for inbound messages. Exploitation could lead to disclosure of sensitive internal information or disruption of gateway operations. The vulnerability has a high severity with a CVSS score of 9.1. Join the discussion | CVE Database V5 | 09/30/2026, 20:17:17 UTC Added: 09/30/2026, 20:34:19 UTC |
0 Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to send crafted requests to internal or unintended network destinations when retrieving a certificate revocation list from inbound messages. Exploitation could lead to disclosure of sensitive internal information or disruption of the gateway's operation. Join the discussion | CVE Database V5 | 09/30/2026, 20:16:00 UTC Added: 09/30/2026, 20:34:19 UTC |
0 CVE-2026-102127 is a high-severity vulnerability in the Kiteworks Email Protection Gateway involving improper restriction of XML external entity references. When an optional, non-default message-processing feature is enabled, a remote unauthenticated attacker can send a crafted message that exploits the XML parser to read files accessible to the gateway service account, including sensitive cryptographic keys and credentials. This could lead to unauthorized disclosure of critical information. Join the discussion | CVE Database V5 | 09/30/2026, 20:14:56 UTC Added: 09/30/2026, 20:34:23 UTC |
0 CVE-2026-102128 is an improper authentication vulnerability in Kiteworks Email Protection Gateway. It allows a remote, unauthenticated attacker to cause the gateway to act on behalf of a user it has not authenticated and to provision a platform account for an unknown identity. This flaw could enable an attacker to gain control over a platform account without proper authentication. The vulnerability affects versions prior to 9.5.1. The CVSS score is 7.5, indicating high severity. Join the discussion | CVE Database V5 | 09/30/2026, 20:14:40 UTC Added: 09/30/2026, 20:34:23 UTC |
0 CVE-2026-102130 is a high-severity vulnerability in Kiteworks Email Protection Gateway that allows an authenticated administrator to execute arbitrary code. This occurs because the gateway does not sufficiently validate the content of uploaded backups, enabling code injection during the loading process. The vulnerability affects versions prior to 9.5.1. Join the discussion | CVE Database V5 | 09/30/2026, 20:13:58 UTC Added: 09/30/2026, 20:34:23 UTC |
Showing 1 to 10 of 22 results