Kiteworks patches max-severity code execution flaw after warning of zero-day attacks

Vulnerability in Email Protection Gateway could give attackers full root control; 126 vulnerabilities fixed in total

By LineZotpaper
Published
Read Time2 min
Secure file-sharing software provider Kiteworks has released security updates addressing 126 vulnerabilities, including a maximum-severity flaw in its Email Protection Gateway (EPG) that could let unauthenticated remote attackers execute arbitrary code and take full administrative control of the appliance. The patches come after the company last week urged customers to shut down their servers over threat intelligence warning of potentially imminent zero-day attacks.

Kiteworks, formerly known as Accellion, provides secure file-sharing and private content network services to thousands of global corporations and government agencies, with over 100 million end-users. The company’s Private Content Network (PCN) integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms.

The most severe vulnerability, tracked as CVE-2026-54154, affects all Email Protection Gateway releases before version 9.4.1 and was reported through Kiteworks’ bug bounty program on YesWeHack. According to a Wednesday advisory from the company, the flaw results from "a combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway" that potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, escalate to full administrative (root) control of the appliance. The attack requires low complexity and no user interaction.

Alongside the maximum-severity issue, Kiteworks patched 11 critical vulnerabilities in both the Core and EPG components, including authentication bypass, admin account takeover, stored cross-site scripting (XSS), improper access control, and improper authentication flaws.

Last week, the company urged customers to shut down their servers after receiving threat intelligence warning of a potentially imminent zero-day cyberattack. On Monday, Kiteworks lifted the precautionary advisory after patching a critical vulnerability and brought all hosted customer systems back online. The company stated it found no evidence of compromise or suspicious activity but has not yet shared additional details on the fixed vulnerability or assigned a CVE ID for that specific issue.

Threat watchdog Shadowserver currently tracks nearly 400 Kiteworks instances exposed on the Internet, though it provides no information on how many have been patched or are honeypots.

§

Analysis

Why This Matters

  • Kiteworks serves thousands of global corporations and government agencies with over 100 million end-users, making a fully exploitable remote code execution flaw a significant supply-chain risk.
  • The company’s prior warning to shut down servers suggests threat actors may have been actively targeting the vulnerability before patches were available.
  • With nearly 400 instances still exposed online, the patching window is critical to prevent widespread compromise.

Background

Kiteworks (formerly Accellion) provides secure file-sharing and private content network services used by large enterprises and government organizations. The company’s Email Protection Gateway is a component of its PCN platform. Accellion was the target of a major cyberattack in 2021 involving a zero-day vulnerability in its legacy file-sharing appliance, which impacted numerous high-profile organizations. This history makes Kiteworks a high-value target for attackers.

Key Perspectives

Kiteworks: The company acted on threat intelligence by issuing an emergency server shutdown advisory and quickly patched the vulnerabilities. It states it found no evidence of compromise and has released updates for all affected versions. Customers and end-users: Organizations running Kiteworks appliances face urgent patching requirements. Those with unpatched EPG instances risk complete compromise of their secure file-sharing infrastructure. Security researchers and attackers: The reported vulnerability chain (path traversal, code injection, missing authentication) represents a serious exploit path that low-skill attackers could potentially weaponize quickly. The fact that the flaw went through a bug bounty program suggests coordinated disclosure.

What to Watch

  • Rate at which exposed Kiteworks instances (currently ~400) are patched or taken offline.
  • Whether threat actors release exploit code for CVE-2026-54154 now that details are public.
  • Whether Kiteworks provides further details on the critical vulnerability patched following the zero-day advisory.
  • Any reports of attempted or successful exploitation in the wild.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.