Tech News
← Home  ·  All topics

Email Protection Gateway

1 GoKawiil brief on this topic

Kiteworks fixes max-severity code execution flaw in Email Protection Gateway

Kiteworks released patches addressing 126 vulnerabilities across its Private Content Network platform, including a critical bug tracked as CVE-2026-54154 affecting its Email Protection Gateway. The flaw, found via Kiteworks' bug bounty program, could let an unauthenticated attacker chain path traversal, code injection, and missing authentication issues to gain root control of an appliance without user interaction. The company also patched 11 other critical flaws spanning authentication bypass, admin takeover, and XSS issues, fixing all affected EPG versions before 9.4.1.