PT-2026-103970 · Kiteworks · Kiteworks Email Protection Gateway
CVE-2026-54154
·
Published
2026-10-01
·
Updated
2026-10-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Kiteworks Email Protection Gateway versions prior to 9.4.1
Description
A maximum severity flaw allows unauthenticated remote attackers to execute arbitrary code and gain root control of the appliance. The issue results from a chain of missing authentication, path traversal, and code injection stemming from input-handling flaws in publicly reachable endpoints. The attack requires low complexity and no user interaction. Approximately 400 exposed systems have been identified by Shadowserver.
Recommendations
Update Kiteworks Email Protection Gateway to version 9.4.1 or later.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiteworks Email Protection Gateway