Kiteworks has released security updates to address 126 vulnerabilities in its products, including a critical vulnerability in the Email Protection Gateway solution, commonly abbreviated as EPG, that could give a remote, unauthenticated attacker the ability to execute code and take full control of the targeted device.
The vulnerability is tracked as CVE-2026-54154 and was discovered through Kiteworks' bug bounty program on the YesWeHack platform. According to the company's details, exploitation relies on a chain of path traversal and code injection flaws, as well as missing authentication at publicly exposed endpoints. The attack requires no user interaction, nor does it require the attacker to have any prior privileges.
What changes in practice?
All Kiteworks Email Protection Gateway versions earlier than 9.4.1 are affected, while a fix is available in version 9.4.1 and later versions. Kiteworks says that chaining these vulnerabilities could have enabled remote code execution, followed by the exploitation of additional local vulnerabilities to gain full administrative control with root privileges.
The fix is part of a broader package that also addressed 11 serious vulnerabilities in Core and EPG components, including authentication bypass, administrative account takeover, stored XSS attacks, and issues involving access control and authentication mechanisms.
Why does this matter?
EPG is part of the Private Content Network, a platform that combines enterprise email, managed file transfer, file sharing, APIs, and web forms. According to the source material, Kiteworks is used by thousands of companies and government entities worldwide, while the number of users on its private network exceeds 100 million. Therefore, the vulnerability's significance is not limited to a single mail server, but extends to a component that may be connected to multiple content and file workflows within organizations.
Shadowserver is currently observing approximately 400 Kiteworks instances exposed to the internet, but it does not clarify how many systems have had the updates installed or represent honeypots. This visibility gap leaves the actual exposure status unknown.
Unresolved security context
In the previous week, Kiteworks asked customers to shut down their servers after receiving intelligence warning of a potential and imminent zero-day attack. The company then lifted the precautionary measure on Monday, brought hosted systems back online, and said it had found no evidence of compromise or suspicious activity. However, the company did not publish additional details about the vulnerability addressed in that warning, and has not yet assigned it a CVE identifier.
Accordingly, the current fix is clear in terms of the affected versions, but the relationship between CVE-2026-54154 and the vulnerability that prompted the earlier precautionary shutdown remains unconfirmed in the available information. The practical priority for EPG owners is to verify the version and update systems earlier than 9.4.1, while reviewing access logs for unusual activity.