Kiteworks fixes max‑severity code execution flaw in Email Protection Gateway
Admins running affected Kiteworks Email Protection Gateway versions now need to patch to restore a secure baseline and re‑expose systems with more confidence.
Kiteworks has released patches for 126 vulnerabilities in its Private Content Network products, including a maximum‑severity remote code execution flaw in its Email Protection Gateway (EPG). The critical bug, tracked as CVE-2026-54154, allows unauthenticated attackers to gain code execution on EPG appliances through a low‑complexity chain involving path traversal, code injection, and missing authentication, potentially leading to full root control. All EPG versions prior to 9.4.1 are affected, with fixes available in version 9.4.1 and later, and Kiteworks disclosed that the issue was found via its bug bounty program on YesWeHack. The same patch set also addresses 11 other critical issues, including authentication bypass, admin account takeover, stored XSS, improper access control, and improper authentication in Core and EPG components. The company had temporarily advised customers to shut down servers due to threat intelligence indicating a possible imminent zero‑day attack, then restored hosted systems after patching a separate critical vulnerability, reporting no signs of compromise, while Shadowserver currently sees about 400 Kiteworks instances exposed online.
Why it matters
For organizations that rely on Kiteworks EPG, this turns an urgent containment situation into a remediation task with a clear end point: upgrade to a fixed release and bring systems back online with reduced risk of takeover. The breadth of fixes, including multiple other critical issues, also means past deployments may have been exposed on several fronts, so treating this as a comprehensive security reset rather than a single‑bug fix is likely to shape how security teams review and harden their Kiteworks footprint.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer