Kiteworks Patches 126 Vulnerabilities, Including Max-Severity RCE in Email Protection Gateway
Secure file-sharing giant **Kiteworks** has released a comprehensive security update, addressing a staggering 126 vulnerabilities across its platform. This includes a critical, maximum-severity flaw (**CVE-2026-54154**) in its **Email Protection Gateway (EPG)**, which could allow unauthenticated remote code execution and full administrative control.
File-sharing software provider **Kiteworks**, formerly known as **Accellion**, has rolled out a significant security update to mitigate 126 vulnerabilities within its **Private Content Network (PCN)** platform. Among these fixes is a critical remote code execution (RCE) vulnerability impacting its **Email Protection Gateway (EPG)** security solution.
The **EPG** is a vital component of the **Kiteworks PCN**, which integrates various enterprise communication tools, including email, **Managed File Transfer (MFT)**, and file sharing, serving thousands of global corporations and government agencies with over 100 million end-users.
### Max-Severity Flaw in EPG
The most severe vulnerability, tracked as **CVE-2026-54154**, was identified through **Kiteworks'** bug bounty program on **YesWeHack**. This flaw allows unprivileged remote attackers to achieve code execution and ultimately take over a targeted **EPG** appliance. The attack chain involves path traversal, code injection, and missing authentication, requiring low complexity and no user interaction.
**Kiteworks** elaborated on the flaw in an advisory, stating, "A combination of input-handling flaws in publicly reachable endpoints of the **Kiteworks Email Protection Gateway** potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, to escalate to full administrative (root) control of the appliance."
This vulnerability affects all **Kiteworks Email Protection Gateway** releases prior to version 9.4.1. Users are strongly advised to update to version 9.4.1 or later immediately.
### Broader Security Patches
Beyond the **EPG** RCE, **Kiteworks** has also addressed 11 other critical vulnerabilities. These include authentication bypasses, admin account takeovers, stored cross-site scripting (XSS), improper access control, and improper authentication issues affecting both the Core and **EPG** components of the platform.
### Prior Zero-Day Alert
Last week, **Kiteworks** took the unusual step of urging customers to shut down their servers proactively. This precautionary measure followed threat intelligence indicating a potential imminent zero-day cyberattack. The company lifted the advisory after implementing a critical patch and reported no evidence of compromise or suspicious activity across its hosted customer systems. Details on that specific vulnerability, including a **CVE** ID, are yet to be publicly shared.
### Exposure on the Internet
Monitoring service **Shadowserver** currently tracks nearly 400 **Kiteworks** instances exposed to the internet. However, it does not provide data on how many of these have been patched or are honeypots, underscoring the urgency for all users to apply the latest security updates.