Tech News
← Home  ·  All topics

Private Content Network

2 GoKawiil briefs on this topic

Kiteworks fixes max-severity code execution flaw in Email Protection Gateway

Kiteworks released patches addressing 126 vulnerabilities across its Private Content Network platform, including a critical bug tracked as CVE-2026-54154 affecting its Email Protection Gateway. The flaw, found via Kiteworks' bug bounty program, could let an unauthenticated attacker chain path traversal, code injection, and missing authentication issues to gain root control of an appliance without user interaction. The company also patched 11 other critical flaws spanning authentication bypass, admin takeover, and XSS issues, fixing all affected EPG versions before 9.4.1.

Kiteworks restores customer systems after patching critical flaw

Kiteworks, formerly Accellion, asked customers globally to shut down servers over the weekend after federal intelligence authorities warned of a possible imminent cyberattack. By Monday, the company restored all hosted customer systems, saying continuous monitoring found no evidence of compromise or abnormal activity. It also disclosed it had patched a critical vulnerability affecting under 1% of customers, tied to a feature it has not named.