Build2 publishers2 min readPublished Updated
Kiteworks patches a no-login CVSS 10.0 code-injection flaw in its Email Protection Gateway
Kiteworks fixed CVE-2026-54154, a CVSS 10.0 flaw letting unauthenticated attackers run code on its Email Protection Gateway, in version 9.4.1. Other EPG flaws disclosed the same day are fixed only in 9.5.1, so internet-facing gateways should go straight to that release.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The CVSS v3.1 vector rates the attack as network-based and low in complexity, with no user interaction required.
- Kiteworks has not published which EPG endpoint is affected or what a malicious request looks like.
- Three weakness classes are assigned, CWE-22, CWE-94 and CWE-306, though the write-up notes they do not settle the order an exploit uses them in.
- The public advisory does not report any exploitation of the flaw in the wild.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint A WAF in front of EPG has no published endpoint or request pattern to match against, so restricting who can reach the gateway is the stopgap, and only until the patch is applied.
- cost With no vendor IoCs, showing a gateway was not hit depends on access logs, process-creation audit logs and configuration histories that standard system logs may not capture.
- exposure A compromised gateway could put its configuration, credentials, encryption keys and message processing in reach, though the write-up labels this inference with no confirmed cases.
The advisory went out on 2026-09-30 [2]. The dev.to write-up that summarises it lays out a successful attack in three steps [19]:
1. The attacker has a network path to an EPG release older than 9.4.1 [19]. 2. A crafted request reaches the public endpoint and the injected code runs on the appliance [19]. 3. The attacker chains further local weaknesses to get root [5].
Step three is conditional. Kiteworks says root requires additional local weaknesses chained after code execution [5]. Steps one and two need nothing but reachability. According to Kiteworks, the flaw is in input handling on externally reachable EPG endpoints [4]. The bug class is input handling, on an appliance bought to inspect other people's input. The write-up's severity basis notes that EPG deployments may be exposed to the internet and says patching should be prioritized for that reason [18].
The 10.0 assumes a network attacker who can reach the endpoint, at low attack complexity [3]. Before the patch is in, step one is the only part an operator controls. The write-up recommends isolating gateway management and the target endpoints from the internet, with access limited to trusted sources, until the update is applied [11]. That cuts the set of attackers who meet the score's assumption down to the sources on the allow list [3][11].
The write-up's hunting list is specific. The first place to check is the reverse proxy or WAF in front of EPG, for unknown source IPs, anomalous paths, and whether those requests drew errors or successes [15]. On the appliance itself, the signs are shells or utilities launched by web processes, and local administrator accounts being created, modified or logged into [15]. The Kiteworks management console records configuration changes, encryption key or certificate updates, and connector modifications [16]. Network records should be checked for outbound traffic from EPG to unknown destinations [16]. Mail flow gives supporting evidence: sudden gaps in message tracking logs, unusual queue backlogs, changed delivery rules [20].
The two same-day advisories are an EPG access-control issue and a stored XSS in Kiteworks Core, both listed against 9.5.1 [10]. The Core entry means the gateway is not the only Kiteworks component to check. The write-up's instruction is to verify the applied release against each fix, one advisory at a time [9].
What to watch
- Kiteworks or outside researchers publishing the vulnerable endpoint or request details, giving defenders something to filter on and attackers something to build from.
- Any report of in-the-wild exploitation of CVE-2026-54154, or Kiteworks adding indicators of compromise to the advisory.
- Identification of the local weaknesses needed to turn code execution into root, and whether any of them is covered by the 9.5.1 access-control fix.