Kiteworks Patches 126 Vulnerabilities, Including Critical CVE-2026-54154
Secure file-sharing software company Kiteworks has released a security update addressing 126 vulnerabilities, including a maximum-severity flaw affecting its Email Protection Gateway (EPG) security solution.
EPG is a component of the Kiteworks Private Content Network (PCN), which unifies enterprise email, managed file transfer (MFT), file sharing, APIs, and web forms on a single platform.
Formerly known as Accellion, Kiteworks serves thousands of global enterprises and government agencies. Its private content network has more than 100 million end users.
Kiteworks fixes critical authentication and access control flaws
As part of the security patch release, Kiteworks also fixed 11 critical vulnerabilities affecting core and EPG components. The flaws include authentication bypasses, administrator account takeovers, stored cross-site scripting (XSS), improper access control, and improper authentication issues.
The maximum-severity vulnerability, tracked as CVE-2026-54154, was reported through YesWeHack’s Kiteworks bug bounty program.
A successful exploit could allow an unprivileged, remote attacker to execute code and take control of a targeted EPG appliance. The attack uses a combination of path traversal, code injection, and low-complexity missing-authentication vulnerabilities and does not require user interaction.
CVE-2026-54154 affects all Kiteworks Email Protection Gateway releases before version 9.4.1. The vulnerability is patched in version 9.4.1 and later.
“A combination of input handling flaws in the publicly reachable endpoint of the Kiteworks Email Protection Gateway could allow an unauthenticated, remote attacker to execute arbitrary code and potentially escalate to full administrative (root) control of the appliance by chaining further local weaknesses,” Kiteworks said in Wednesday’s advisory.
Kiteworks recently warned customers about a possible zero-day attack
Kiteworks last week called on customers to shut down their servers after receiving a threat intelligence alert about a possible impending zero-day cyberattack.
The company lifted the precautionary advisory on Monday after patching critical vulnerabilities and bringing all hosted customer systems back online. Kiteworks said it found no evidence of a breach or suspicious activity.
However, Kiteworks has not shared additional details about the fixed vulnerabilities and has not yet assigned a CVE ID for easier tracking.
Approximately 400 Kiteworks instances exposed online
Threat watchdog Shadowserver is currently tracking approximately 400 Kiteworks instances that are publicly available on the Internet.
There is currently no information about how many of those instances have been patched or how many may be honeypots.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



