Kiteworks has patched CVE-2026-54154, a maximum-severity flaw in its Email Protection Gateway (EPG) that lets an unauthenticated remote attacker chain path traversal, code injection, and missing authentication into arbitrary code execution, then escalate to root on the appliance. The attack is low-complexity and needs no user interaction. It was reported through the company's YesWeHack bug bounty program and affects every EPG release before 9.4.1.
The fix shipped inside a larger batch of 126 vulnerabilities, 11 of them rated critical across the Core and EPG components. Those 11 cover authentication bypass, admin account takeover, stored XSS, improper access control, and improper authentication. CVE-2026-54154 is the one that gets a remote attacker root, but anyone running EPG is sitting on a stack of critical auth and access-control bugs until they upgrade.
EPG is part of the Kiteworks Private Content Network, which bundles enterprise email, Managed File Transfer, file sharing, APIs, and web forms into one platform. Kiteworks, formerly Accellion, says the PCN has more than 100 million end-users across thousands of corporations and government agencies. An appliance that sits on the email boundary for that many organisations is a high-value target, and the bug class here is the worst kind for it: input-handling flaws in publicly reachable endpoints.
That phrasing comes from Kiteworks' own advisory, published Wednesday: "A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, to escalate to full administrative (root) control of the appliance."
There is a second thread the advisory does not fully close. Last week Kiteworks urged customers to shut down their servers after receiving threat intelligence about a potentially imminent zero-day attack. It lifted that precautionary advisory on Monday once it had patched a critical vulnerability and brought hosted customer systems back online, reporting no evidence of compromise or suspicious activity. The company has not shared details on that fixed vulnerability or assigned it a CVE. Whether it is the same bug as CVE-2026-54154 or a separate one is not stated.
What to do is straightforward: upgrade EPG to 9.4.1 or later. The harder question is what to do about appliances that were internet-facing on a pre-9.4.1 build. Shadowserver currently tracks nearly 400 Kiteworks instances exposed on the internet, with no breakdown of how many are patched or are honeypots. Unauthenticated RCE to root leaves no good reason to assume an exposed box is clean, and no-evidence findings on systems a vendor hosts tell you nothing about an appliance running in your own environment. If you run your own EPG appliance and it has been reachable on a vulnerable version, patch it and then go looking, rather than patching and moving on.
Top comments (0)