Kiteworks patches max-severity CVE-2026-54154 in EPG
Kiteworks patched CVE-2026-54154, a maximum-severity flaw in its Email Protection Gateway that lets an unauthenticated remote attacker chain path traversal, code injection and missing authentication into arbitrary code execution and root. The fix is part of a batch of 126 vulnerabilities, 11 rated critical; all EPG releases before 9.4.1 are affected.
- CVE-2026-54154 allows unauthenticated remote code execution and root escalation
- All EPG releases before 9.4.1 are affected; fix ships in a batch of 126 flaws
- 11 vulnerabilities across Core and EPG are rated critical
- Shadowserver tracks nearly 400 Kiteworks instances exposed to the internet
Read next
Security