Kiteworks Patches Max-Severity Code Injection Flaw
Secure file-sharing software company Kiteworks has rolled out comprehensive security updates to resolve 126 vulnerabilities, highlighted by a max-severity code injection flaw in its Email Protection Gateway solution.

Overview of the Kiteworks Security Updates
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution as reported by BleepingComputer.
The EPG component is part of the broader Kiteworks Private Content Network (PCN), which integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single unified platform. Formerly known as Accellion, Kiteworks serves thousands of global corporations and government agencies, with its Private Content Network supporting over 100 million end-users worldwide.
Details of the Maximum-Severity Vulnerability
Tracked as CVE-2026-54154, the maximum-severity vulnerability was reported through Kiteworks' bug bounty program on YesWeHack. Successful exploitation can allow remote, unprivileged threat actors to gain code execution and completely take over a targeted EPG appliance.
Attackers can achieve this by exploiting a chain of path traversal, code injection, and missing authentication weaknesses in low-complexity attacks that require no user interaction. The flaw affects all Kiteworks Email Protection Gateway releases prior to version 9.4.1 and has been addressed in version 9.4.1 and later.
Kiteworks explained the mechanism of the vulnerability in a Wednesday advisory, noting that a combination of input-handling flaws in publicly reachable endpoints allowed unauthenticated remote attackers to achieve arbitrary code execution.
Additional Vulnerabilities Addressed in Core and EPG
As part of the same set of security patches , Kiteworks also fixed 11 critical authentication bypass, admin account takeover, stored cross-site scripting (XSS), improper access control, and improper authentication vulnerabilities across both its Core and EPG components.
These updates are designed to harden the overall software architecture against potential exploitation chains that could otherwise lead to administrative compromise or data exposure.
Precautionary Server Shutdown and Incident Context
Last week, Kiteworks urged customers to shut down their servers after receiving threat intelligence warning of a potentially imminent zero-day cyberattack. The company later lifted its precautionary advisory after patching a critical vulnerability and brought all hosted customer systems back online.
Kiteworks stated that it found no evidence of active compromise or suspicious activity related to the warning. Further details regarding the earlier patched critical vulnerability were noted by Kiteworks patches critical flaw, brings customer systems online as administrative operations resumed.
Internet Exposure and Threat Watchdog Statistics
Threat watchdog Shadowserver currently tracks nearly 400 Kiteworks instances exposed directly on the public internet. However, the organization provides no specific telemetry indicating how many of these exposed systems have already been patched or whether any serve as honeypots.
Administrators operating affected Kiteworks environments are strongly encouraged to verify their current version numbers and apply the latest security updates immediately to mitigate potential remote code execution risks.
Sources
- BleepingComputerKiteworks patches max severity code injection vulnerability