Kiteworks fixes max-severity code execution flaw in Email Protection Gateway
Kiteworks released patches addressing 126 vulnerabilities across its Private Content Network platform, including a critical bug tracked as CVE-2026-54154 affecting its Email Protection Gateway. The flaw, found via Kiteworks' bug bounty program, could let an unauthenticated attacker chain path traversal, code injection, and missing authentication issues to gain root control of an appliance without user interaction. The company also patched 11 other critical flaws spanning authentication bypass, admin takeover, and XSS issues, fixing all affected EPG versions before 9.4.1.
GoKawiil's interpretation of the reporting above, not reported fact.
Kiteworks' Private Content Network reportedly serves over 100 million end-users across corporations and government agencies, so an unauthenticated remote code execution bug in a public-facing component could expose a wide base of sensitive file-sharing and email infrastructure. The timing follows a precautionary shutdown advisory Kiteworks issued just last week over threat intelligence suggesting an imminent zero-day attack, which may indicate heightened attacker interest in the platform. Organizations relying on EPG should treat patching as urgent given the low complexity and no-interaction nature of the exploit chain described.
- Kiteworks patched 126 vulnerabilities, including a maximum-severity flaw (CVE-2026-54154) in its Email Protection Gateway.
- The bug allows unauthenticated remote attackers to chain flaws for full root control without user interaction, fixed in EPG 9.4.1+.
- The patch follows a recent precautionary shutdown advisory tied to warnings of a possible imminent zero-day attack.
Source: bleepingcomputer.com, 2026-10-01
Published there as: “Kiteworks patches max severity code injection vulnerability”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.