chiprook
← Security
SecurityOctober 9, 2026, 13:25

Kiteworks patches max-severity CVE-2026-54154 in EPG

Kiteworks patched CVE-2026-54154, a maximum-severity flaw in its Email Protection Gateway that lets an unauthenticated remote attacker chain path traversal, code injection and missing authentication into arbitrary code execution and root. The fix is part of a batch of 126 vulnerabilities, 11 rated critical; all EPG releases before 9.4.1 are affected.

Kiteworks patches max-severity CVE-2026-54154 in EPG
#Kiteworks
Read next
Security

Kiteworks patches max severity code injection vulnerability

Security

GitLab patches CVSS 9.9 CVE-2026-90970 in AI Gateway

Security

Cisco patches critical NX-API RCE CVE-2026-76471 in NX-OS

Security

Elementor Pro CVE-2026-32475: patching doesn't remove the webshell