Kiteworks has fixed a maximum-severity flaw in its Email Protection Gateway (EPG). The flaw, CVE-2026-54154, lets a remote attacker with no credentials run arbitrary code with root privileges. It is the worst of 125 security advisories that Kiteworks published in its GitHub advisory repository on 30 September 2026. The batch covers Kiteworks Core, EPG, Secure Data Forms (SDF) and MFT Server. Twelve of the advisories are rated critical. Several of those let an unauthenticated attacker take over user accounts, including administrator accounts. EPG sits at the email edge of organisations that buy Kiteworks to control the exchange of sensitive content, so administrators should check versions today. Every EPG and Core appliance should be on 9.5.1, the highest fixed release referenced in the batch. Kiteworks has published no workarounds.
CVE-2026-54154: Unauthenticated Root Code Execution in Kiteworks EPG
The advisory for CVE-2026-54154 (GHSA-5xhq-9wq3-rvj6) is brief. Kiteworks states the impact as: "A remote attacker may be able to execute arbitrary code with root privileges." The root-cause description says only that "Multiple issues were addressed with improved input validation." The advisory maps the issue to three weakness classes:
- CWE-22, improper limitation of a pathname to a restricted directory (path traversal);
- CWE-94, improper control of generation of code (code injection);
- CWE-306, missing authentication for a critical function.
Taken together, those CWE labels describe a chain. A function that should require authentication can be reached without it, and attacker-supplied input can escape intended directories and end up as executed code. Kiteworks has not said which component, endpoint or parameter is involved, and it has not published a technical write-up. We are not going to guess. The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. That means the attack works over the network with low complexity, needs no privileges and no user interaction, and has a changed scope. The scope change means a successful attack can affect resources beyond the vulnerable component itself.
Every EPG version before 9.4.1 is affected. The fix is EPG 9.4.1 or later. Kiteworks credits the researchers wlayzz, icare and truff, who reported the issue through its YesWeHack bug bounty programme.
Record status: On 4 October 2026 the CVE.org API returned "record does not exist" for CVE-2026-54154, and NVD had no entry for it. The GitHub advisory is live and is currently the only authoritative description. Several other identifiers in the batch, including CVE-2026-85065, were also unpublished on CVE.org when we checked. Security scanners that rely only on NVD may therefore not flag these issues yet.
The 9.8 Account-Takeover Flaws in Kiteworks Core and EPG
Three advisories rated CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) share the same stated impact: "A remote attacker may be able to gain access to user accounts."
CVE-2026-102115: Kiteworks Core password reset bypass
This is the most fully documented flaw in the batch, because its CVE record has been published. The record says Kiteworks Core "did not correctly validate a parameter submitted to the password reset workflow". It goes on: "An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges."
Kiteworks maps it to CWE-640 (weak password recovery mechanism), CWE-697 (incorrect comparison) and CWE-1287 (improper validation of specified type of input). All Core versions before 9.5.0 are affected. Accounts that sign in through an external identity provider are outside the scope the CVE record describes, because the record specifies a locally stored password.
CVE-2026-85065 and CVE-2026-85066: EPG authentication failures
Both flaws affect EPG before 9.5.0. CVE-2026-85065 is mapped to CWE-287 (improper authentication) and CWE-306. CVE-2026-85066 is mapped to CWE-306 and CWE-640, which points to another weakness in password recovery. Kiteworks' only explanation is "An authentication issue was addressed with improved checks."
The Rest of the Critical Tier
The other critical advisories all affect Core or EPG:
| CVE | Product | CVSS 3.1 | Stated impact (Kiteworks) | CWE | Fixed in |
|---|---|---|---|---|---|
| CVE-2026-54154 | EPG | 10.0 | Arbitrary code execution with root privileges | CWE-22, CWE-94, CWE-306 | 9.4.1 |
| CVE-2026-102115 | Core | 9.8 | Access to user accounts (password reset bypass) | CWE-640, CWE-697, CWE-1287 | 9.5.0 |
| CVE-2026-85065 | EPG | 9.8 | Access to user accounts | CWE-287, CWE-306 | 9.5.0 |
| CVE-2026-85066 | EPG | 9.8 | Access to user accounts | CWE-306, CWE-640 | 9.5.0 |
| CVE-2026-102149 | EPG | 9.4 | Access to user accounts (access control issue) | CWE-306, CWE-639 | 9.5.1 |
| CVE-2026-102147 | Core | 9.3 | Administrative access (injection issue) | CWE-79 | 9.5.1 |
| CVE-2026-102106 | EPG | 9.1 | Modification of administrative configuration | CWE-287 | 9.5.0 |
| CVE-2026-102095, -102102, -102103, -102104, -102105 | EPG | 9.1 | Access to internal network resources | CWE-918 (SSRF) | 9.5.0 |
CVE-2026-102147 is a cross-site scripting flaw. Its vector includes user interaction (UI:R), so a legitimate user has to load attacker-controlled content before the attacker gains administrative access. The five 9.1 server-side request forgery (SSRF) flaws matter because an email gateway usually has network reach into internal mail and directory infrastructure. That makes it a useful pivot for an attacker. Below the critical tier, the batch has 49 high, 52 medium and 12 low-severity advisories, with fixes landing in 9.2.1, 9.3.0, 9.3.1, 9.4.0, 9.4.1, 9.5.0 and 9.5.1, depending on the product.
Exploitation Status
None of the advisories we reviewed says the flaws have been exploited, and Kiteworks has published no indicators of compromise. All of the issues reached Kiteworks through its private YesWeHack bug bounty, not through incident response. None of the CVEs is listed in CISA's Known Exploited Vulnerabilities catalog.
Still, we would not read the lack of exploitation reports as a reason to wait. Kiteworks has disclosed 125 advisories at once, and each one names the vulnerable product and the fixed version. That gives anyone comparing patched and unpatched builds a detailed map. Managed file transfer and secure-exchange appliances have repeatedly been targeted in mass data-theft campaigns, because one compromised gateway gives access to the sensitive files and messages of many users.
Affected and Fixed Versions
| Product | Advisories (30 Sept 2026) | Fixed releases referenced | Minimum safe target |
|---|---|---|---|
| Kiteworks Email Protection Gateway | 28 | 9.3.1, 9.4.0, 9.4.1, 9.5.0, 9.5.1 | 9.5.1 |
| Kiteworks Core | 66 | 9.2.1, 9.3.0, 9.3.1, 9.4.0, 9.4.1, 9.5.0, 9.5.1 | 9.5.1 |
| Kiteworks Secure Data Forms | 28 | 9.2.1, 9.3.1, 9.4.0, 9.4.1, 9.5.0, 9.5.1 | 9.5.1 |
| Kiteworks MFT Server | 3 | 9.4.1 | 9.4.1 |
Defensive Playbook for Kiteworks Administrators
- Upgrade first. Move every EPG, Core and SDF deployment to 9.5.1, and MFT Server to at least 9.4.1. The bare minimum for CVE-2026-54154 is EPG 9.4.1, but that release still leaves the 9.5.0 and 9.5.1 account-takeover fixes uninstalled.
- Inventory versions across the estate. Kiteworks is often deployed as clustered appliances. Confirm that every node, including disaster-recovery and staging nodes, reports the target version after the upgrade.
- Limit exposure of administrative interfaces. Until upgrades are verified, restrict EPG and Core administrative and management endpoints to trusted management networks or a VPN. This is our editorial recommendation, not vendor guidance; Kiteworks lists no workarounds.
- Review password-reset activity. CVE-2026-102115 lets an attacker reset a password without the emailed link. Pull the audit trail for password resets and new sign-ins on local accounts since before 30 September, and focus on administrators. If a reset has no matching user request, treat it as a possible compromise.
- Rotate credentials if in doubt. If an appliance was internet-facing on a vulnerable build, rotate the passwords of local administrators and service accounts, and review the administrative configuration for unexpected changes (relevant to CVE-2026-102106).
- Watch egress from the gateway. The five SSRF flaws let an EPG appliance be used to reach internal resources. Alert on unusual outbound connections from EPG hosts to internal management or cloud metadata addresses.
- Track the CVE records. Many identifiers in this batch were not yet published on CVE.org or NVD. Do not wait for scanners to raise them; use the vendor's fixed versions as the source of truth.
The advisories do not give version-check commands or log paths. Use the version shown in the Kiteworks administration console, and the platform's own audit log export, as the record of truth for the checks above.



