Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-02 · updated: 2026-10-02 · tags: [incident, global, zero-day] · confidence: high · severity: high · affected_sectors: [global] · au_impact: false

Kiteworks released updates fixing 126 vulnerabilities across its Private Content Network, including a maximum-severity flaw in the Email Protection Gateway tracked as CVE-2026-54154. The flaw chains path traversal, code injection and missing authentication in publicly reachable endpoints, letting an unauthenticated remote attacker achieve arbitrary code execution and, through chained local weaknesses, escalate to full administrative (root) control of the appliance; it affects all EPG releases before 9.4.1. Eleven further critical flaws cover authentication bypass, admin account takeover, stored XSS and access-control failures in the Core and EPG components — the vulnerability feed lists Core OS command injection (CVE-2026-102120) and admin takeover via stored XSS (CVE-2026-102147) among them. The patching follows last week's step of urging customers to shut EPG servers down over threat intelligence of a potential zero-day; the advisory was lifted on Monday with no evidence of compromise found, and no CVE has been assigned for the underlying flaw. Shadowserver tracks nearly 400 exposed instances.

Attribute Detail
Sector Global (Macro)
Date 2026-10-02
Source BleepingComputer
Reliability Tier 1
CVEs CVE-2026-102120, CVE-2026-102147, CVE-2026-54154