Kiteworks patches max severity code injection vulnerability
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email.
By Dillip Chowdary β’ Oct 01, 2026 β’ Source: BleepingComputer
What broke in Kiteworks max severity code injection
What broke: P1: ~110 words. P2: ~111 words. Section 2 Who is exposed: P1: ~104 words. P2: ~106 words. Section 3 What to do now: * P1: ~
EPG is a component of the Kiteworks Private Content Network (PCN), which integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single platform. Formerly known as Accellion, Kiteworks provides services to thousands of global corporations and government agencies, and its Private Content Network has over 100 million end-users.
Who is exposed by Kiteworks max severity code injection

As part of the same set of security patches, Kiteworks has also fixed 11 critical authentication bypass, admin account takeover, stored cross-site scripting (XSS), improper access control, and improper authentication vulnerabilities in the Core and EPG components. Tracked as CVE-2026-54154, the maximum-severity vulnerability was reported through Kiteworks' bug bounty program on YesWeHack.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
What to do now about Kiteworks max severity code injection
Successful exploitation can let remote threat actors without privileges gain code execution and take over the targeted EPG appliance by exploiting a chain of path traversal, code injection, and missing authentication in low-complexity attacks that don't require user interaction. See the full write-up from BleepingComputer via the source link for quotes and complete context.
The flaw affects all Kiteworks Email Protection Gateway releases before 9.4.1 and is now patched in versions 9.4.1 or later. Last week, Kiteworks urged customers to shut down their servers after receiving threat intelligence warning of a potentially imminent zero-day cyberattack.
How the Kiteworks max severity code injection issue works
The company lifted the precautionary advisory on Monday after patching a critical vulnerability and brought all hosted customer systems back online, and said that it found no evidence of compromise or suspicious activity. However, Kiteworks has yet to share additional details on the fixed vulnerability and has not yet assigned a CVE ID for easy tracking.
What is still unknown about Kiteworks max severity code injection
Threat watchdog Shadowserver currently tracks nearly 400 Kiteworks instances exposed on the Internet, but provides no information on how many have already been patched or are honeypots. See the full write-up from BleepingComputer via the source link for quotes and complete context.
Developer Action Items
- β Inventory whether Kiteworks patches max severity runs in prod, CI, staging, or on laptops before you debate severity.
- β Pull the vendor advisory for CVE-2026-54154 and patch from that page β not from a social recap.
- β If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
- β Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.
Author
Dillip Chowdary
Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.
Related on Tech Bytes
βHomePadβ could launch in these four colors, per leaker
Read β
Announcing Ranveer Singh as Brand Ambassador for Ray-Ban and Ray-Ban Meta in India alongβ¦
Read β
Qualcomm Unveils Linux Preview on Snapdragon X2 to Accelerate Upstream ARM Laptops
Read β
Actions Runner Controller release 0.15.0
Read β
Today's Tech Pulse briefing
Full briefing β
Advertisement