Skip to content

Kiteworks patches max-severity RCE in Email Protection Gateway

CVE-2026-54154, scored 10.0, chains path traversal, code injection and missing auth into unauthenticated root RCE on Kiteworks Email Protection Gateway before 9.4.1.

Published 2 min read

Kiteworks has patched CVE-2026-54154, a CVSS 10.0 flaw in its Email Protection Gateway (EPG) that lets an unauthenticated attacker reach remote code execution and full root control of the appliance. The fix ships in EPG 9.4.1, part of a release that closes 126 vulnerabilities, 11 of them critical.

What the bug does

Per the vendor's GitHub security advisory GHSA-5xhq-9wq3-rvj6, CVE-2026-54154 is a chain of input-handling flaws in publicly reachable endpoints — path traversal, code injection, and missing authentication — that together allow arbitrary code execution. Chaining additional local weaknesses escalates that to root on the gateway.

The advisory assigns the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — network-reachable, low complexity, no privileges, no user interaction, scope changed. That is the full-10 profile: an appliance that sits at the email perimeter, taken over pre-auth. The flaw was reported through Kiteworks' YesWeHack bug bounty, per BleepingComputer.

Affected versions

  • Vulnerable: all Kiteworks Email Protection Gateway releases before 9.4.1.
  • Fixed: 9.4.1 or later.

Exploitation status

No active exploitation is reported. The GHSA advisory does not cite in-the-wild activity, and neither does BleepingComputer. But a pre-auth, no-interaction 10.0 on an internet-facing security appliance is exactly the profile that gets a public PoC and opportunistic scanning fast — treat the clock as started at disclosure, not at first exploitation.

Action checklist

  1. Inventory EPG appliances and confirm the running version. Anything below 9.4.1 is exploitable.
  2. Upgrade to 9.4.1+ now. This is a perimeter device; there is no compensating control that beats patching.
  3. Restrict exposure in the interim — the chain needs reachable endpoints, so limit who can hit the EPG management and processing surfaces from the internet.
  4. Hunt for compromise on any appliance that was internet-exposed before patching: unexpected processes, new files in web-reachable paths, and outbound connections from the gateway.

Context

This is the second max-severity Kiteworks advisory to land in recent weeks, after the critical Advanced Forms flaw patched in 9.5.1. Kiteworks appliances concentrate exactly the data attackers want — regulated file transfers and email — and the vendor's own bulk advisory this round (126 CVEs, 11 critical) signals a product line under sustained scrutiny. If you run EPG, assume it is a named target and patch on that basis.

Related stories