Skip to main content
CybersecurityVulnerability Management

Kiteworks Fixes Code Injection Flaw in Email Protection Gateway

Rows of computer equipment in a server room with a single Email Protection Gateway appliance in the foreground.

"A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, to escalate to full administrative (root) control of the appliance," Kiteworks said in an advisory.

CVE-2026-54154: a max-severity chain in the Email Protection Gateway

Kiteworks has released patches addressing a maximum-severity vulnerability tracked as CVE-2026-54154 in its Email Protection Gateway (EPG) component. The company said the flaw stems from a chain of path traversal, code injection, and missing authentication that — in low-complexity, unauthenticated attacks requiring no user interaction — could allow remote actors to achieve code execution and take over an EPG appliance.

The vulnerability affects all Kiteworks EPG releases prior to 9.4.1 and is fixed in versions 9.4.1 and later. Kiteworks reported that the flaw was disclosed through its bug bounty program on YesWeHack.

Wide patch set: 126 vulnerabilities, including 11 critical fixes

The EPG fix is part of a broader update that addresses 126 vulnerabilities across the Kiteworks platform. Among those were 11 critical issues in the Core and EPG components, which Kiteworks listed as including authentication bypass, admin account takeover, stored cross-site scripting (XSS), improper access control, and improper authentication.

Those bundled fixes indicate the company treated the release as a large-scale remediation effort, not a single isolated patch.

Kiteworks platform scope and exposure

Kiteworks — the company formerly known as Accellion — delivers a Private Content Network (PCN) that integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single platform. The vendor says the PCN supports thousands of corporations and government agencies and has over 100 million end-users.

Independent trackers show external exposure: Shadowserver currently reports nearly 400 Kiteworks instances visible on the public Internet. Shadowserver's count does not indicate how many of those instances have already received the newly released patches or whether any are honeypots, the tracker says.

Customer guidance, shutdown advisory, and incident timeline

Last week Kiteworks urged customers to shut down their servers after receiving threat intelligence warning of a potentially imminent zero-day cyberattack. The company later lifted that precautionary advisory on Monday after applying a patch for a critical vulnerability and bringing all hosted customer systems back online. Kiteworks said it found no evidence of compromise or suspicious activity related to the precautionary event.

Despite patching, Kiteworks has not published additional technical details about that earlier fixed vulnerability and has not assigned a CVE identifier for it to assist with external tracking.

What this means for technologists, affected enterprises, and adversaries

  • Technologists and security teams: Administrators running Kiteworks Email Protection Gateway should verify EPG versions and update to 9.4.1 or later where necessary; the advisory named an unauthenticated chain leading to full appliance takeover, and the fix was released through the vendor's update process and its bug bounty feed.
  • Affected enterprises and procurement leaders: Organizations that rely on Kiteworks' Private Content Network — which the vendor says serves thousands of corporations and government agencies and more than 100 million end-users — will need to confirm hosted or on-premises instances have been patched and review the vendor's advisory timeline that included a temporary shutdown recommendation.
  • Adversaries and threat actors: The flaw's characterization — unauthenticated, low-complexity, no user interaction required — makes unpatched EPG appliances high-value targets; Shadowserver's report of nearly 400 Internet-exposed instances highlights potential targets, though the tracker does not indicate patch status or honeypots.

Kiteworks' deployment of a broad set of patches, including the fix for CVE-2026-54154, addresses an immediate and high-risk failure mode in its Email Protection Gateway. But two facts remain salient from the company's own advisory and independent tracking: the earlier precautionary shutdown and subsequent lack of a CVE for that earlier fix, and Shadowserver's count of nearly 400 Internet-exposed instances without public data on how many have been remediated. Those items will determine how effectively the risk was reduced in practice.

Original reporting: https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/