Kiteworks, formerly known as Accellion, provides secure file-sharing and private content network services to thousands of global corporations and government agencies, with over 100 million end-users. The company’s Private Content Network (PCN) integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms.
The most severe vulnerability, tracked as CVE-2026-54154, affects all Email Protection Gateway releases before version 9.4.1 and was reported through Kiteworks’ bug bounty program on YesWeHack. According to a Wednesday advisory from the company, the flaw results from "a combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway" that potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, escalate to full administrative (root) control of the appliance. The attack requires low complexity and no user interaction.
Alongside the maximum-severity issue, Kiteworks patched 11 critical vulnerabilities in both the Core and EPG components, including authentication bypass, admin account takeover, stored cross-site scripting (XSS), improper access control, and improper authentication flaws.
Last week, the company urged customers to shut down their servers after receiving threat intelligence warning of a potentially imminent zero-day cyberattack. On Monday, Kiteworks lifted the precautionary advisory after patching a critical vulnerability and brought all hosted customer systems back online. The company stated it found no evidence of compromise or suspicious activity but has not yet shared additional details on the fixed vulnerability or assigned a CVE ID for that specific issue.
Threat watchdog Shadowserver currently tracks nearly 400 Kiteworks instances exposed on the Internet, though it provides no information on how many have been patched or are honeypots.