Vulnerabilities fixed in this release: 126 (Source: BleepingComputer, reporting on Kiteworks' security updates (October 1, 2026))
The guard at the door is also a door
Companies buy email security products to keep attackers out. Kiteworks sells one called the Email Protection Gateway (EPG). But the gateway is itself a server. Outsiders can reach it, and its software can have flaws of its own. Kiteworks' latest patch round shows what that means in practice.
BleepingComputer reported that Kiteworks has released fixes for 126 vulnerabilities. The most serious is CVE-2026-54154, rated maximum severity. It sits in the EPG, one part of the Kiteworks Private Content Network. That platform brings business email, file transfer, file sharing, APIs and web forms together in one place.
How the attack works
CVE-2026-54154 is not a single bug. It is a chain of three weaknesses: path traversal, code injection and missing authentication.
Path traversal lets an attacker reach files outside the folder a program should stay in. Code injection slips in input that the system then runs as a command. Missing authentication means a door that should ask for a login does not.
BleepingComputer reports that a remote attacker with no privileges could chain these to run code and take over the appliance. The attacks are low-complexity. They need no action from any user. The report does not describe any use of the flaw against a real system.
Kiteworks' advisory describes flaws in how publicly reachable endpoints handle input. It says the flaws "potentially allowed" an unauthenticated attacker to run code. With additional local weaknesses added to the chain, the attacker could reach full administrative control, known as root. Root is the highest level of access on a machine.
The lesson here is about chains. Linked together, these weaknesses could give an outsider control of the whole appliance. The last step to root depends on those extra local weaknesses.
We also see a broader point. Weaknesses that look minor one by one can matter more once they are linked. That is our interpretation. The source does not say how each flaw was scored on its own.
Who is affected and what fixes it
Every EPG release before 9.4.1 is affected. Version 9.4.1 or later contains the fix.
The flaw was reported through Kiteworks' bug bounty program, which runs on YesWeHack. A bounty program pays outsiders to report problems to the vendor.
Shadowserver, which monitors internet threats, tracks nearly 400 Kiteworks instances exposed online. BleepingComputer says Shadowserver gives no information on how many are patched or how many are honeypots, which are decoy systems. So the figure is not a count of vulnerable systems.
A shutdown request came days before the patch
The release followed an unusual request. Shortly before it, Kiteworks asked customers to switch their servers off as a safeguard. The company cited a tip that attackers might be about to use a zero-day. A zero-day is a flaw that attackers know about before a fix exists.
A notice like that forces a fast decision about whether to take email and file-transfer systems offline.
Kiteworks withdrew the request on Monday. By its account, a fix for a critical flaw was in place and hosted customer systems were running again. The company said it had seen no sign of a break-in or odd activity.
Two caveats apply. Kiteworks has not yet shared details of that earlier fix. It has not assigned a CVE ID either. The source does not say whether it is the same flaw as CVE-2026-54154. Without an ID, customers may find it harder to track in their own tools.
What leaders should ask their teams
Start with inventory. Do we run Kiteworks EPG, and which version? Any version before 9.4.1 should be upgraded. Hosted customers can ask Kiteworks to confirm their status in writing.
Then ask about exposure. Which of our security and file-transfer appliances can be reached from the internet? Does each one need to be? Gateways often sit at the edge by design. That makes patch speed and network placement part of the security decision.
Finally, ask about the next notice. If a vendor asks us to shut a system down tomorrow, who decides? What stops working when it is switched off? A team that has answered this in advance loses less time.
A security product is still software. It deserves the same patch tracking as anything else facing the internet.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: BleepingComputer.





