Bleepingcomputer Kiteworks Patches Code Injection Vulnerability in Email Protection Gateway
Article Content
- •CVE-2026-54154 allows remote code execution on Kiteworks EPG before version 9.4.1.
- •Kiteworks patched 126 vulnerabilities, including 11 critical flaws.
- •Customers were previously advised to shut down servers due to a potential zero-day threat.
Kiteworks has patched a maximum-severity vulnerability (CVE-2026-54154) affecting its Email Protection Gateway (EPG), which could allow unauthenticated remote attackers to execute arbitrary code. The flaw, reported through Kiteworks' bug bounty program, affects all EPG versions prior to 9.4.1. Kiteworks also addressed 126 vulnerabilities in total, including 11 flaws related to authentication bypass and improper access control. The company had previously advised customers to shut down servers due to threat intelligence indicating a potential zero-day attack. However, after applying the patches, they confirmed no evidence of compromise. Another CVE (CVE-2026-102097) was published on September 30, 2026, indicating similar vulnerabilities in EPG versions before 9.5.0. The current status is that all affected systems should be updated to version 9.4.1 or later.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Kiteworks and CVE-2026-102097 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of Kiteworks are affected?
What should I do if I'm using Kiteworks EPG?
Is there evidence of exploitation?
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…