Vulnerabilities
56 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-24782 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters. Upgrade Kiteworks to version 9.3.0 or later to receive a patch. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2026-29092 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2026-28270 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue. NVD description · AI analysis pending | 7.2 group max | 2% |
| — | ||
| CVE-2026-28269 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could be exploited to overwrite critical system files and gain elevated access. Version 9.2.0 contains a patch. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2025-53939 | Kiteworks is a private data network (PDN). Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a shared folder could lead to unexpectedly elevate another user's permissions on the share. This issue has been patched in version 9.1.0. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-53900 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of roles and permissions in Kiteworks MFT on managing Connections could lead to unexpected escalation of privileges for authorized users. This issue has been patched in version 9.1.0. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2022-24110 | Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2021-31586 +1 in the same advisory: …31585 | Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search. NVD description · AI analysis pending | 8.8 group max | 44% |
| — | ||
| CVE-2021-27730 +1 in the same advisory: …27731 | Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2021-27104 | Unauthenticated OS Command Injection in Accellion FTA Admin Endpoints CVE-2021-27104 is an OS command injection flaw (CWE-78) in Accellion's File Transfer Appliance (FTA), affecting versions 9_12_370 and earlier. It is triggered by sending a crafted POST request to various admin endpoints, and the CVSS vector (no privileges, no user interaction, network-accessible) indicates it can be exploited by an unauthenticated remote attacker. Successful exploitation yields full OS command execution on the appliance, giving the attacker control sufficient for data theft, web shell deployment, and follow-on ransomware/extortion operations. Organizations running Accellion FTA appliances — typically deployed as internet-facing large-file transfer endpoints by enterprises, government agencies, and universities — are affected. The flaw is being actively exploited in the wild: it was added to CISA's KEV catalog on 2021-11-03 with known ransomware use (notably the Clop/FINEST data-theft extortion campaign, including the breach of security firm Qualys), and it carries a high EPSS score of 56.7% (99th percentile). The fixed version is FTA_9_12_380 and later. Do: Upgrade Accellion FTA to version FTA_9_12_380 or later per vendor instructions; the flaw is on CISA's KEV list with known ransomware use, so patching is urgent for internet-facing appliances. Until patched, restrict or firewall access to FTA admin endpoints from the internet, and review logs and the appliance for signs of command injection or web shell (e.g., DEWMODE-related) compromise given the active data-theft extortion campaign. | 9.8 group max | 57% | KEV ransomware |
| moderate≈1,000-10,000 internet-exposed FTA appliances (enterprise appliance with a customer base in the low thousands of organizations) | |
| CVE-2019-5623 +1 in the same advisory: …5622 | Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection'). NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2016-9500 +1 in the same advisory: …9499 | Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, c Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting. NVD description · AI analysis pending | 6.1 group max | 5% | PoC |
| — | |
| CVE-2017-9421 | Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token. NVD description · AI analysis pending | 6.5 | 1% |
| — | ||
| CVE-2017-8303 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter. NVD description · AI analysis pending | 9.8 group max | 24% | PoC |
| — | |
| CVE-2016-5664 | Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI. Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI. NVD description · AI analysis pending | 4.3 | 2% |
| — |