type: cve · created: 2026-10-02 · updated: 2026-10-02 · tags: [cve, rce, kiteworks, zero-day] · confidence: medium · severity: critical · affected_sectors: [global] · au_impact: false
Kiteworks released updates fixing 126 vulnerabilities across its Private Content Network, including a maximum-severity flaw in the Email Protection Gateway tracked as CVE-2026-54154; the flaw chains path traversal, code injection and missing authentication in publicly reachable endpoints, letting an unauthenticated remote attacker achieve arbitrary code execution and, through chained local weaknesses, escalate to full administrative control. CVE-2026-54154 has no NVD record (unpublished or reserved at the time of writing), so no CVSS score is available; the "maximum severity" rating is the vendor's and the digest's.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-54154 |
| CVSS | Maximum severity (vendor); no NVD score published as at 2026-10-04 |
| Vendor / product | Kiteworks — Email Protection Gateway |
| Reported | 2026-10-01 |