chiprook
← Security
SecurityOctober 1, 2026, 20:51

Kiteworks patches max severity code injection vulnerability

Kiteworks released security updates fixing 126 vulnerabilities, including a maximum-severity flaw in its Email Protection Gateway. CVE-2026-54154 chains path traversal, code injection and missing authentication to let unauthenticated attackers execute code and gain root on the appliance. All EPG releases before 9.4.1 are affected.

Kiteworks patches max severity code injection vulnerability
#Kiteworks
Read next
Security

WatchGuard Patches Critical Fireware OS Code Injection Flaw

Security

Forminator WordPress plugin hit by 9.1-severity vulnerability

Security

TeamViewer urges users to patch five severe flaws immediately

Security

OpenSSL patches high-severity DTLS flaw leaking heap memory