Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/kiteworks/email-protection-gateway

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to make crafted requests to internal or unintended network destinations when rendering message content with external resource references. Exploitation could lead to disclosure of sensitive internal information or unintended actions on internal systems. The vulnerability has a high severity with a CVSS score of 9.1. No explicit patch information is provided, so users should verify vendor advisories for remediation status.

Join the discussion

CVE-2026-102106 is an improper authentication vulnerability in the Kiteworks Email Protection Gateway administrative service. The service does not consistently enforce administrator authentication, allowing an attacker referencing a valid administrator account to bypass password checks. This can enable unauthorized creation, modification, or deletion of internal users and managed domains, as well as changes to security configurations. Deleting a managed domain can remove its user accounts and potentially lock out legitimate administrators.

Join the discussion

CVE-2026-102108 is a high-severity vulnerability in Kiteworks Email Protection Gateway that allows an authenticated administrator with specific queue-management privileges to submit crafted serialized objects to a cluster management interface. These objects are deserialized without sufficient validation, potentially enabling arbitrary code execution under the gateway service account. The vulnerability affects versions prior to 9.5.0.

Join the discussion

CVE-2026-102116 is a path traversal vulnerability in Kiteworks Email Protection Gateway that allows an authenticated administrator to write files outside intended directories. This flaw can lead to remote code execution by causing the application to execute malicious files written by the attacker. The vulnerability affects versions prior to 9.5.0. It has a high severity score of 7.2 and requires high privileges to exploit.

Join the discussion

CVE-2026-102119 is a path traversal vulnerability in the Kiteworks Email Protection Gateway. It affects an optional, non-default administrative feature that allows an authenticated administrator to move files outside the intended directory. This could enable arbitrary code execution on the underlying system. The vulnerability affects versions prior to 9.5.0. The CVSS score is 7.2, indicating high severity.

Join the discussion

Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to send crafted requests to internal or unintended network destinations during online certificate status checks for inbound messages. Exploitation could lead to disclosure of sensitive internal information or disruption of gateway operations. The vulnerability has a high severity with a CVSS score of 9.1.

Join the discussion

Kiteworks Email Protection Gateway versions before 9.5.0 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows a remote, unauthenticated attacker to cause the gateway to send crafted requests to internal or unintended network destinations when retrieving a certificate revocation list from inbound messages. Exploitation could lead to disclosure of sensitive internal information or disruption of the gateway's operation.

Join the discussion

CVE-2026-102127 is a high-severity vulnerability in the Kiteworks Email Protection Gateway involving improper restriction of XML external entity references. When an optional, non-default message-processing feature is enabled, a remote unauthenticated attacker can send a crafted message that exploits the XML parser to read files accessible to the gateway service account, including sensitive cryptographic keys and credentials. This could lead to unauthorized disclosure of critical information.

Join the discussion

CVE-2026-102128 is an improper authentication vulnerability in Kiteworks Email Protection Gateway. It allows a remote, unauthenticated attacker to cause the gateway to act on behalf of a user it has not authenticated and to provision a platform account for an unknown identity. This flaw could enable an attacker to gain control over a platform account without proper authentication. The vulnerability affects versions prior to 9.5.1. The CVSS score is 7.5, indicating high severity.

Join the discussion

CVE-2026-102130 is a high-severity vulnerability in Kiteworks Email Protection Gateway that allows an authenticated administrator to execute arbitrary code. This occurs because the gateway does not sufficiently validate the content of uploaded backups, enabling code injection during the loading process. The vulnerability affects versions prior to 9.5.1.

Join the discussion

Showing 1 to 10 of 22 results

Filters:Package: pkg:github/kiteworks/email-protection-gateway
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses