Kiteworks patches max severity code injection vulnerability

Kiteworks patches max severity code injection vulnerability
Kiteworks has issued security updates for 126 vulnerabilities, including CVE-2026-54154, a critical flaw in its Email Protection Gateway that could allow unauthenticated remote code execution and full root takeover. The company also fixed multiple critical issues in Core and EPG, after previously warning customers to shut down servers due to a suspected imminent zero-day attack.#Kiteworks #CVE-2026-54154 #EmailProtectionGateway

Keypoints

  • Kiteworks patched 126 vulnerabilities across its platform.
  • CVE-2026-54154 affects the Email Protection Gateway before version 9.4.1.
  • The flaw can lead to remote code execution without authentication.
  • Kiteworks also fixed 11 critical issues in Core and EPG components.
  • The company previously warned customers of a possible zero-day attack and later restored hosted systems.

Read More: https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/