bleeping-computer · Crawled Oct 1, 2026

Kiteworks patches max severity code injection vulnerability

Read original article ↗

AI Summary

Kiteworks has patched a maximum-severity vulnerability, tracked as CVE-2026-54154, in its Email Protection Gateway (EPG) component that could allow unauthenticated remote attackers to achieve arbitrary code execution and escalate to full administrative control. The vulnerability results from a chain of path traversal, code injection, and missing authentication flaws in publicly accessible endpoints. It affects all EPG releases prior to version 9.4.1, and successful exploitation does not require user interaction. Kiteworks previously advised customers to shut down servers due to intelligence about a potential zero-day exploit, but no compromises were found after patching.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.