Vulnerability
Published 2026-10-01
Verified 2026-10-01

Kiteworks Email Protection Gateway CVE-2026-54154 (CVSS 10.0): unauth code injection → root — patch EPG 9.4.1+ (126-vuln batch 1 Oct)

Kiteworks GitHub advisory GHSA-5xhq-9wq3-rvj6 / CVE-2026-54154 (BleepingComputer 1 October 2026): a maximum-severity chain of path traversal, code injection, and missing authentication on publicly reachable Email Protection Gateway (EPG) endpoints can let an unauthenticated remote attacker achieve arbitrary code execution and escalate to full administrative (root) control of the appliance. CVSS 3.1 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Affects all Kiteworks EPG releases before 9.4.1; fixed in 9.4.1+. Same 1 Oct patch batch also addresses 11 other critical issues (auth bypass, admin takeover, stored XSS, access control) across Core and EPG, totaling 126 vulnerabilities. Reported via YesWeHack bug bounty. Distinct from desk kiteworks-shutdown-20260926 (26–27 Sep LE-intel precautionary shutdown / Advanced Forms defect; no CVE then). Shadowserver tracks ~400 internet-exposed Kiteworks instances. Primary: Kiteworks GHSA; wire: BleepingComputer 1 Oct.

Product
Kiteworks Email Protection Gateway (EPG) / Private Content Network
Versions
Affected: all Kiteworks Email Protection Gateway versions prior to 9.4.1. Fixed: EPG 9.4.1+. Broader 1 Oct batch also patches Core/EPG criticals (11 critical + additional highs/mediums; 126 total per BleepingComputer).
CVSS
(CVSS 3.1 Critical; GHSA)
Exploited in Australia?
unknown
Patch to
Upgrade Kiteworks Email Protection Gateway to 9.4.1 or later immediately; apply the full 1 Oct security batch for Core/EPG. Until patched: remove internet exposure of EPG management/public endpoints; treat Accellion-era MFT footprints as high-value. Confirm Advanced Forms customers from the 26–27 Sep shutdown window are also on current releases (see kiteworks-shutdown-20260926).

Primary: Kiteworks GHSA-5xhq-9wq3-rvj6 — CVE-2026-54154 EPG code injection (Critical 10.0) · Vendor: Kiteworks security advisory (GitHub) — CVE-2026-54154 · CVE: CVE-2026-54154 · BleepingComputer — Kiteworks patches max-severity EPG code injection (1 Oct 2026)

vulnerabilities cloud network