Kiteworks patches max severity code injection vulnerability

Kiteworks, a leading provider of secure file-sharing solutions to thousands of global corporations and government agencies, has released critical security patches to address 126 vulnerabilities, including a maximum-severity code injection flaw that could allow remote attackers to take control of its Email Protection Gateway (EPG) appliances. The vulnerability, tracked as CVE-2026-54154, affects all versions of EPG prior to 9.4.1 and has been patched in versions 9.4.1 and later.

Kiteworks’ Private Content Network (PCN) is a comprehensive platform that integrates email, file transfer, and web forms into one secure environment, used by over 100 million end-users worldwide. The Email Protection Gateway is a critical component of PCN, designed to protect users from phishing attacks and other email-borne threats. However, the recent vulnerability has exposed this protection mechanism to potential exploitation.

According to Kiteworks, an attacker could exploit the vulnerability by chaining a series of low-complexity attacks that don’t require user interaction. By leveraging a path traversal flaw, code injection, and missing authentication, an unauthenticated remote attacker could gain arbitrary code execution and escalate to full administrative control of the EPG appliance.

The vulnerability was discovered through Kiteworks’ bug bounty program on YesWeHack, highlighting the importance of responsible disclosure in identifying and addressing critical security flaws. While Kiteworks has patched the vulnerability and lifted a precautionary advisory that urged customers to shut down their servers, it remains unclear how many instances have already been compromised or exposed online.

Shadowserver, a threat watchdog organization, currently tracks nearly 400 Kiteworks instances exposed on the internet, but provides no information on patch status or honeypot activity. As the cybersecurity landscape continues to evolve, organizations relying on Kiteworks’ solutions must prioritize timely patching and vulnerability management to prevent potential exploitation of this critical flaw.

For end-users and administrators, this security alert serves as a reminder of the importance of regular software updates and patches to maintain the integrity of their systems. It is essential to stay informed about vulnerabilities affecting your organization’s infrastructure and take proactive measures to mitigate risks. In this case, ensure that all EPG appliances are updated to version 9.4.1 or later to prevent potential exploitation of the CVE-2026-54154 vulnerability.


Source: Bleeping Computer — 2026-10-01