Kiteworks Security Patch Fixes Critical Code Injection Vulnerability
Kiteworks resolves 126 security vulnerabilities, including a high-severity flaw in its Protection Gateway component.
Overview of the Vulnerabilities
Kiteworks, a secure file-sharing platform, has issued patches to address 126 security flaws across its product suite. The most critical issue, a high-severity vulnerability in the Protection Gateway (EPG) security solution, could allow remote code execution. The EPG is a core part of the Kiteworks Private Content Network (PCN), which consolidates enterprise file transfer, secure sharing, and API integrations.
Key Vulnerabilities Identified
The resolved issues include 11 critical vulnerabilities in the Core and EPG components. These encompass authentication bypass flaws, admin account takeover risks, stored cross-site scripting (XSS) vulnerabilities, and improper access control mechanisms.
Details of the High-Severity Flaw
The most severe flaw, designated CVE-2026-54154, was disclosed via Kiteworks’ YesWeHack bug bounty program. Exploitation allows unauthenticated attackers to execute arbitrary code on EPG appliances through path traversal, code injection, and authentication gaps. The attack chain requires no user interaction and operates with low complexity, enabling full administrative control of the system.
Impact and Mitigation
The flaw affects all EPG releases prior to version 9.4.1. Mitigation is available in updates 9.4.1 and later. Kiteworks’ advisory noted that the vulnerability stems from input-handling weaknesses in publicly accessible endpoints, which could permit remote code execution and privilege escalation to root-level access.
Previous Actions and Current Status
Kiteworks previously issued a temporary shutdown directive for customer servers following threat intelligence about an imminent zero-day exploit. This precaution was lifted on Monday after critical vulnerabilities were addressed, with the firm confirming no signs of compromise or malicious activity in affected systems.
Unassigned CVE Identifier
Despite the patch deployment, Kiteworks has not yet assigned a Common Vulnerabilities and Exposures (CVE) identifier for the fixed flaw, complicating tracking efforts. Shadowserver, a cybersecurity monitoring organization, reports approximately 400 Kiteworks instances exposed to the internet, though it has not disclosed how many have been patched or if any represent honeypot setups.
Related Security Incidents
The updates follow recent disclosures of similar vulnerabilities in other platforms, including a critical Roundcube flaw exploited for code injection attacks and a separate incident involving compromised Pentagon personnel data. Security agencies have also issued warnings about pre-authentication remote code execution flaws in MikroTik RouterOS, underscoring ongoing challenges in securing enterprise infrastructure.
“The vulnerability stems from input-handling weaknesses in publicly accessible endpoints, which could permit remote code execution and subsequent privilege escalation to root-level access,” according to Kiteworks’ advisory.
