Kiteworks patches max severity code injection vulnerability
Kiteworks released security updates fixing 126 vulnerabilities, including a maximum-severity flaw in its Email Protection Gateway. CVE-2026-54154 chains path traversal, code injection and missing authentication to let unauthenticated attackers execute code and gain root on the appliance. All EPG releases before 9.4.1 are affected.
- CVE-2026-54154 lets unauthenticated attackers execute code and gain root
- 126 vulnerabilities fixed, including 11 critical flaws in Core and EPG
- All Email Protection Gateway releases before 9.4.1 are affected
- Shadowserver tracks nearly 400 Kiteworks instances exposed online
Read next
Security