INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Kiteworks Patches Multiple Code Injection Vulnerabilities Across Customer Systems

| 2026-09-28 09:44 CRITICAL LOW EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On October 1, 2026, a potentially imminent zero-day cyberattack was reported to Kiteworks through its bug bounty program on YesWeHack, tracked as CVE-2026-54154. The maximum-severity vulnerability affects all Kiteworks Email Protection Gateway releases before version 9.4.1 and has been patched in versions 9.4.1 or later. This flaw allows remote threat actors without privileges to gain code execution and take over the targeted EPG appliance through a chain of path traversal, code injection, and missing authentication in low-complexity attacks that don't require user interaction. As part of its response, Kiteworks urged customers to shut down their servers last week before patching the vulnerability on Monday, bringing all hosted customer systems back online with no evidence of compromise or suspicious activity.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-65660, CVE-2026-54154 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-65660CVE-2026-65660 CVE-2026-54154CVE-2026-54154
Target & Sectors
NORTH_AMERICA NORTH_AMERICA governmentgovernment technologytechnology
Incident Timeline
‎February 2021
Five Eyes members issued a joint security advisory in February 2021 warning Accellion customers to block Internet access to vulnerable servers and update them.
tactic Extortion
target_region FIVE_EYES
organisation Eyes
‎2026/09/24
Kiteworks prompted customers to immediately shut down their servers due to a potential zero-day cyberattack.
‎September 27th
Kiteworks lifted the shutdown recommendation for all customers as of September 27th, following a patch to address a critical code injection vulnerability.
‎2026/09/28
Threat actors exploited a max-severity code injection vulnerability in Kiteworks Email Protection Gateway releases before 9.4.1, which was later patched in versions 9.4.1 or later.
organisation Zero-Click Data Exfiltration
victims 100 end users
infrastructure 9.5.1
organisation Kiteworks
organisation Advanced Forms
organisation DPE
organisation MFT
organisation Reddit
organisation the Kiteworks Private Content Network
organisation PCN
organisation Managed File Transfer
organisation Accellion
organisation Mandiant
victims 50 organizations
organisation Kiteworks Advanced Forms
organisation YesWeHack
infrastructure 9.4.1
organisation EPG
organisation the Kiteworks Email Protection Gateway
organisation NFL
organisation CHANEL
organisation Kroger
organisation Singtel
organisation Australian Securities and Investments Commission
organisation ASIC
organisation the Office of the Washington State
organisation Shell
organisation the Reserve Bank of New Zealand
organisation Kiteworks File Transfer Appliance
organisation FTA
victims 300 customers
Tactical Metrics
Metrics
infrastructure
‎9.5.1
Software Version
Metrics
victims
50
Organizations
Metrics
victims
100,000,000
End Users
Metrics
infrastructure
‎9.4.1
Software Version
Metrics
victims
300
Customers
Intelligence Sources