ConciseSignal
Following

Kiteworks fixes severe code injection flaw in email gateway

Kiteworks has released security updates to fix 126 vulnerabilities, including a maximum-severity code injection flaw in its Email Protection Gateway product. The vulnerability, tracked as CVE-2026-54154, could enable remote attackers to gain administrative control over affected systems without needing user interaction. Kiteworks had previously urged some customers to temporarily shut down servers but now confirms systems are secure, with no evidence of compromise found so far.

Why it mattersKiteworks provides secure file-sharing and email protection for thousands of businesses and government agencies. Vulnerabilities like these can put sensitive communications at risk if exploited before patches are applied.

Sources covering this

BleepingComputerKiteworks patches max severity code injection vulnerability1:51 PM →
Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity