INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Kiteworks Patches Multiple Code Injection Vulnerabilities Across Customer Systems
| 2026-09-28 09:44 CRITICAL LOW EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On October 1, 2026, a potentially imminent zero-day cyberattack was reported to Kiteworks through its bug bounty program on YesWeHack, tracked as CVE-2026-54154. The maximum-severity vulnerability affects all Kiteworks Email Protection Gateway releases before version 9.4.1 and has been patched in versions 9.4.1 or later. This flaw allows remote threat actors without privileges to gain code execution and take over the targeted EPG appliance through a chain of path traversal, code injection, and missing authentication in low-complexity attacks that don't require user interaction. As part of its response, Kiteworks urged customers to shut down their servers last week before patching the vulnerability on Monday, bringing all hosted customer systems back online with no evidence of compromise or suspicious activity.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-65660, CVE-2026-54154 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-65660CVE-2026-65660
CVE-2026-54154CVE-2026-54154
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
technologytechnology
Incident Timeline
February 2021
Five Eyes members issued a joint security advisory in February 2021 warning Accellion customers to block Internet access to vulnerable servers and update them.
Click on any entity below to view its context and source!
tactic
Extortion
Five Eyes members also issued a
joint security advisory
in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.
target_region
FIVE_EYES
Five Eyes members also issued a
joint security advisory
in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.
organisation
Eyes
Five Eyes members also issued a
joint security advisory
in February 2021 about these attacks and subsequent extortion attempts, warning Accellion customers to block Internet access to vulnerable servers and update them to block the attacks.
2026/09/24
Kiteworks prompted customers to immediately shut down their servers due to a potential zero-day cyberattack.
September 27th
Kiteworks lifted the shutdown recommendation for all customers as of September 27th, following a patch to address a critical code injection vulnerability.
2026/09/28
Threat actors exploited a max-severity code injection vulnerability in Kiteworks Email Protection Gateway releases before 9.4.1, which was later patched in versions 9.4.1 or later.
Click on any entity below to view its context and source!
organisation
Zero-Click Data Exfiltration
Related:
Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Related:
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Related:
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
Related:
‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
victims
100 end users
Formerly known as Accellion, Kiteworks provides services to thousands of global corporations and government agencies, and its Private Content Network has over 100 million end-users.
Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users.
infrastructure
9.5.1
Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version.”
organisation
Kiteworks
Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability.
Kiteworks patches max severity code injection vulnerability.
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability.
organisation
Advanced Forms
“Customers with self-hosted Advanced Forms should contact Customer Support for assistance.
organisation
DPE
All other products, including the DPE, file collaboration, file transfer, email encryption, APIs, and MFT, are unaffected,” a copy of the email shared on
Reddit
reads.
organisation
MFT
All other products, including the DPE, file collaboration, file transfer, email encryption, APIs, and MFT, are unaffected,” a copy of the email shared on
Reddit
reads.
EPG is a component of the Kiteworks Private Content Network (PCN), which integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single platform.
Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.
organisation
Reddit
All other products, including the DPE, file collaboration, file transfer, email encryption, APIs, and MFT, are unaffected,” a copy of the email shared on
Reddit
reads.
organisation
the Kiteworks Private Content Network
EPG is a component of the Kiteworks Private Content Network (PCN), which integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single platform.
organisation
PCN
EPG is a component of the Kiteworks Private Content Network (PCN), which integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single platform.
Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.
organisation
Managed File Transfer
EPG is a component of the Kiteworks Private Content Network (PCN), which integrates enterprise email, Managed File Transfer (MFT), file sharing, APIs, and web forms into a single platform.
organisation
Accellion
Formerly known as Accellion, it operates a Private Content Network (PCN) that integrates enterprise email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform.
organisation
Mandiant
The company said it had no evidence the security defect was exploited and that it was working with “industry partners, including Mandiant, to share intelligence about the threat”.
victims
50 organizations
“Advanced Forms is enabled for fewer than 1% of our customers, under 50 organizations, and the vulnerability is confined to that product only.
organisation
Kiteworks Advanced Forms
Kiteworks has also patched a critical vulnerability in an unnamed feature used by less than 1% of all customers and advised those with self-hosted Kiteworks Advanced Forms to contact support for further assistance.
organisation
YesWeHack
Tracked as CVE-2026-54154, the maximum-severity vulnerability was reported through Kiteworks' bug bounty program on YesWeHack.
infrastructure
9.4.1
The flaw affects all Kiteworks Email Protection Gateway releases before 9.4.1 and is now patched in versions 9.4.1 or later.
organisation
EPG
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution.
organisation
the Kiteworks Email Protection Gateway
"A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email Protection Gateway potentially allowed an unauthenticated remote attacker to achieve arbitrary code execution and, by chaining additional local weaknesses, to escalate to full administrative (root) control of the appliance,"
Kiteworks explained
in a Wednesday advisory.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Kroger
…stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and multiple universities.
organisation
Singtel
…stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and multiple universities.
organisation
Australian Securities and Investments Commission
…stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and multiple universities.
organisation
ASIC
…stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and multiple universities.
organisation
the
Office of the Washington State
…stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and multiple universities.
organisation
Shell
…campaign led to a stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and mult…
organisation
the
Reserve Bank of New Zealand
…n led to a stream of data breaches impacting many high-profile entities that used the Accellion FTA software to transfer sensitive files, including
cybersecurity firm Qualys
,
energy giant Shell
, the
Reserve Bank of New Zealand
,
supermarket giant Kroger
,
Singtel,
the
Australian Securities and Investments Commission (ASIC)
, the
Office of the Washington State Auditor
, and multiple uni…
organisation
Kiteworks File Transfer Appliance
For instance, the Clop extortion gang, which has a long history of exploiting vulnerabilities in enterprise file-sharing platforms, also
targeted a legacy Kiteworks File Transfer Appliance (FTA) software
in zero-day attacks when the company was still known as Accellion.
organisation
FTA
For instance, the Clop extortion gang, which has a long history of exploiting vulnerabilities in enterprise file-sharing platforms, also
targeted a legacy Kiteworks File Transfer Appliance (FTA) software
in zero-day attacks when the company was still known as Accellion.
victims
300 customers
Accellion
said
at the time that 300 customers used the 20-year-old legacy FTA software, with fewer than 100 of them breached and fewer than two dozen victims appeared "to have suffered significant data theft.
Tactical Metrics
Metrics
infrastructure
9.5.1
Software Version
Click for context!
Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version.”
Metrics
victims
50
Organizations
“Advanced Forms is enabled for fewer than 1% of our customers, under 50 organizations, and the vulnerability is confined to that product only.
Metrics
victims
100,000,000
End Users
Formerly known as Accellion, Kiteworks provides services to thousands of global corporations and government agencies, and its Private Content Network has over 100 million end-users.
Kiteworks provides services to thousands of global corporations and government agencies, and its Private Data Network has over 100 million end-users.
Metrics
infrastructure
9.4.1
Software Version
The flaw affects all Kiteworks Email Protection Gateway releases before 9.4.1 and is now patched in versions 9.4.1 or later.
Metrics
victims
300
Customers
Accellion
said
at the time that 300 customers used the 20-year-old legacy FTA software, with fewer than 100 of them breached and fewer than two dozen victims appeared "to have suffered significant data theft.
Intelligence Sources
SecurityWeek
2026-09-28
BleepingComputer
2026-09-29
Kiteworks patches critical flaw, brings customer systems online
BleepingComputer
BleepingComputer
2026-10-01
Kiteworks patches max severity code injection vulnerability
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:25
Comprehensive Tactical Telemetry
Highly Correlated Entities
27x
organisation
Identified Entity
Zero-Click Data Exfiltration
entity
4x
timeline
Temporal Reference
2026/09/24
date
2x
target region
Target Country
United States
country
2x
industry
Targeted Sector
Government
sector
2x
tactic
Cyber Operation Type
Exfiltration
tactic
2x
vulnerability
Exploited CVE
CVE-2026-65660
cve
2x
infrastructure
Software Version
9.5.1
version
2x
attribution
Attributing Entity
Accellion
authority
Contextual Telemetry
Context Block
14 METRICS
general metric
Netscaler Zero Days
2
netscaler zero days
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
general metric
%
1
%
victims
Organizations
50
organizations
victims
End Users
100,000,000
end users
general metric
Cve-2026
54,154
cve-2026
general metric
Vulnerabilities
126
vulnerabilities
general metric
Critical Authentication Bypass
11
critical authentication bypass
general metric
Kiteworks Instances
400
kiteworks instances
general metric
Most
234
most
target region
Target Region
FIVE_EYES
region
source region
Origin Country
United States
country
victims
Customers
300
customers
general metric
Software
100
software
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.