PT-2026-103970 · Kiteworks · Kiteworks Email Protection Gateway

CVE-2026-54154

·

Published

2026-10-01

·

Updated

2026-10-09

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Kiteworks Email Protection Gateway versions prior to 9.4.1
Description A maximum severity flaw allows unauthenticated remote attackers to execute arbitrary code and gain root control of the appliance. The issue results from a chain of missing authentication, path traversal, and code injection stemming from input-handling flaws in publicly reachable endpoints. The attack requires low complexity and no user interaction. Approximately 400 exposed systems have been identified by Shadowserver.
Recommendations Update Kiteworks Email Protection Gateway to version 9.4.1 or later.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-54154

Affected Products

Kiteworks Email Protection Gateway