Threats·Cloud & SaaSBreakingKiteworks Email Protection Gateway Flaw Rated CVSS 10 Lets Unauthenticated Attackers Run Code as Root, Alongside a Wave of Account-Takeover Bugs (CVE-2026-54154)Kiteworks fixed a CVSS 10 root code-execution flaw in Email Protection Gateway (CVE-2026-54154) and three 9.8 account takeovers. Upgrade EPG and Core to 9.5.1.Daniel Okafor4 Oct 20266 min read