Kiteworks patches max severity code injection vulnerability
Kiteworks patched CVE-2026-54154, an unauthenticated code-injection flaw that can give attackers root on Email Protection Gateway appliances.
Kiteworks patched 126 vulnerabilities, including maximum-severity CVE-2026-54154 in Email Protection Gateway releases before 9.4.1. An unauthenticated attacker can chain path traversal, code injection, and missing authentication to execute code and gain root on the appliance. The update also fixes 11 critical authentication-bypass, admin-takeover, stored XSS, and access-control flaws in Core and EPG. After a precautionary shutdown tied to possible imminent attack intelligence, Kiteworks reported no evidence of compromise; Shadowserver tracks nearly 400 exposed instances.