Kiteworks fixes severe code injection flaw in email gateway
Kiteworks has released security updates to fix 126 vulnerabilities, including a maximum-severity code injection flaw in its Email Protection Gateway product. The vulnerability, tracked as CVE-2026-54154, could enable remote attackers to gain administrative control over affected systems without needing user interaction. Kiteworks had previously urged some customers to temporarily shut down servers but now confirms systems are secure, with no evidence of compromise found so far.
- 126 vulnerabilities addressed in latest Kiteworks update
- Max-severity flaw in Email Protection Gateway patched
- Attackers could execute code and gain admin control remotely
- No evidence found of successful attacks, Kiteworks says
- Company lifted server shutdown after issuing patches
Sources covering this
More in Cybersecurity
Police arrest alleged 16-year-old leader of KillSec ransomware group
An international law enforcement operation has arrested a 16-year-old suspected of leading the KillSec ransomware gang, seized its leak…
New device claims to freeze iPhones to bypass Apple security
A leaked video shows Magnet Forensics, seller of the popular GrayKey hacking tool, claiming its new device can bypass Apple's 72-hour…
Chinese hackers targeted AI policy experts with phishing
Researchers report that a China-linked hacking group used phishing emails to impersonate AI experts and policy officials, targeting…
GrayKey tool reportedly bypasses iPhone Inactivity Reboot
GrayKey, a forensic tool from Magnet Forensics, can reportedly bypass the iPhone's Inactivity Reboot feature, which is designed to…