Skip to content
Kiteworks Patches Code Injection Vulnerability in Email Protection Gateway

Kiteworks Patches Code Injection Vulnerability in Email Protection Gateway

First seen 1 Oct 2026, 16:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 17:05 UTC
  • •CVE-2026-54154 allows remote code execution on Kiteworks EPG before version 9.4.1.
  • •Kiteworks patched 126 vulnerabilities, including 11 critical flaws.
  • •Customers were previously advised to shut down servers due to a potential zero-day threat.

Kiteworks has patched a maximum-severity vulnerability (CVE-2026-54154) affecting its Email Protection Gateway (EPG), which could allow unauthenticated remote attackers to execute arbitrary code. The flaw, reported through Kiteworks' bug bounty program, affects all EPG versions prior to 9.4.1. Kiteworks also addressed 126 vulnerabilities in total, including 11 flaws related to authentication bypass and improper access control. The company had previously advised customers to shut down servers due to threat intelligence indicating a potential zero-day attack. However, after applying the patches, they confirmed no evidence of compromise. Another CVE (CVE-2026-102097) was published on September 30, 2026, indicating similar vulnerabilities in EPG versions before 9.5.0. The current status is that all affected systems should be updated to version 9.4.1 or later.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-102097 published
CVE-2026-102097 disclosed vulnerabilities in Kiteworks EPG, allowing remote code execution.
X
2026-10-01
Kiteworks patches vulnerabilities
Kiteworks released security updates addressing 126 vulnerabilities, including a max-severity flaw.
BleepingComputer

More articles in this cluster (3)

Following this threat?

Track Kiteworks and CVE-2026-102097 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of Kiteworks are affected?
Kiteworks Email Protection Gateway versions prior to 9.4.1 are affected by CVE-2026-54154.
What should I do if I'm using Kiteworks EPG?
Update to version 9.4.1 or later immediately to mitigate the vulnerabilities.
Is there evidence of exploitation?
Kiteworks has not reported any evidence of exploitation following the patching of the vulnerabilities.