Kiteworks security advisory (AV26-988)
Canada's Cyber Centre warns Kiteworks Core, EPG, and Secure Data Forms before 9.5.0 and 9.5.1 need updates.
On October 1, 2026, the Canadian Centre for Cyber Security issued advisory AV26-988 on vulnerabilities in Kiteworks Core, Email Protection Gateway, and Secure Data Forms. As of September 30, 2026, versions prior to 9.5.0 and 9.5.1 are affected. The bulletin lists no CVE identifiers and does not report exploitation. Users and administrators are urged to review Kiteworks security advisories and apply updates as they become available.
- CCCS advisory AV26-988 covers Kiteworks Core, EPG, and Secure Data Forms.
- Builds before 9.5.0 and 9.5.1 are listed as affected.
- No CVE identifiers or active exploitation are mentioned.
- Administrators are told to review Kiteworks advisories and patch.
Full article76 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-988
Date: October 1, 2026
As of September 30, 2026, Kiteworks is affected by vulnerabilities in the following products:
- Kiteworks Core
- Prior to 9.5.0
- Prior to 9.5.1
- Kiteworks Email Protection Gateway (EPG)
- Prior to 9.5.0
- Prior to 9.5.1
- Kiteworks Secure Data Forms (SDF)
- Prior to 9.5.0
- Prior to 9.5.1
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/kiteworks-security-advisory-av26-988