Skip to content
TrustList
News

Kiteworks fixes more than 100 flaws, 12 of them critical, in Core and its Email Protection Gateway: update to 9.5.1

Editorial

By TrustList Editorial

Kiteworks published more than 100 security advisories on 30 September 2026, 12 rated critical, for Core, the Email Protection Gateway, Secure Data Forms and MFT Server. The most severe, a gateway code-injection flaw, is fixed in 9.4.1; update to 9.5.1.

About Kiteworks fixes more than 100 flaws, 12 of them critical, in Core and its Email Protection Gateway: update to 9.5.1

Kiteworks fixes more than 100 flaws, 12 of them critical, in Core and its Email Protection Gateway: update to 9.5.1

1 October 2026 — Kiteworks, whose platform is used by companies and government bodies to exchange sensitive files and email, published a very large batch of security advisories on 30 September 2026. Its advisory repository lists more than 100 new advisories that day, 12 of them rated critical, across Kiteworks Core, the Email Protection Gateway (EPG), Secure Data Forms and MFT Server. Every one is fixed in version 9.5.1 or earlier releases of the 9.4 and 9.5 lines.

Not yet independently verified. The counts are from Kiteworks’ advisory repository as returned on 1 October 2026, which showed 100 advisories published on 30 September before the list was cut off, so the total is at least 100. BleepingComputer, reporting the same release, counts 126 flaws of which 11 are critical; the two counts differ. Kiteworks’ own release notes need a customer login and were not read. We will update this when it can be confirmed, and remove this note.

The most severe flaws

  • CVE-2026-54154, a code-injection flaw in the Email Protection Gateway before version 9.4.1. BleepingComputer describes it as maximum severity and says it was reported through a bug-bounty programme.
  • Authentication bypass in the password-reset workflow in Core (CVE-2026-102115) and in the EPG (CVE-2026-85066), fixed in 9.5.0.
  • Authentication bypass leading to account takeover in the EPG (CVE-2026-85065), fixed in 9.5.0.
  • Administrative account takeover through stored cross-site scripting in Core (CVE-2026-102147), fixed in 9.5.1.
  • Improper access control in the EPG (CVE-2026-102149), fixed in 9.5.1.
  • Several server-side request forgery flaws in the EPG, fixed in 9.5.0.

No exploitation has been reported. BleepingComputer cites Shadowserver as tracking nearly 400 Kiteworks instances exposed to the internet.

Why it matters now

Managed file transfer and secure-email gateways sit at the edge of the network and handle exactly the files attackers want, and products in this category have been mass-exploited before. Kiteworks itself took its systems offline as a precaution on 26 September after warning of a credible threat, and lifted that on 29 September; this release is the full set of fixes that followed. Attackers study large patch releases to find what they fix, so the gap between publication and exploitation can be short.

What to do

  • Update every self-managed Kiteworks Core and Email Protection Gateway to 9.5.1, which covers all the advisories listed above. If you cannot reach 9.5.1 at once, get the EPG to at least 9.4.1 for CVE-2026-54154.
  • Include Secure Data Forms and MFT Server, which also have advisories in the batch.
  • Check exposure: limit the administrative interfaces to trusted networks and review administrator accounts.
  • Review logs around password-reset flows and administrator sign-ins since mid-September.
  • If Kiteworks hosts your instance, ask when it was updated and to which version.

Sources

Categories & features