# Kiteworks patches flaw allowing remote takeover of email gateway

_Published Thursday, October 1, 2026 at 11:12 AM EDT · Security · Latest · Tier 2 — Notable_

![Kiteworks patches flaw allowing remote takeover of email gateway — Primary](https://www.bleepstatic.com/content/hl-images/2026/10/01/Kiteworks.jpg)

Kiteworks released updates addressing 126 vulnerabilities, including a maximum-severity flaw that can let unauthenticated remote attackers take over its Email Protection Gateway. Tracked as CVE-2026-54154, the flaw affects every gateway release before 9.4.1 and is patched in 9.4.1 or later.

Attackers can chain path traversal, code injection and missing authentication to execute code without user interaction, then exploit additional local weaknesses to gain root control. The updates also fix 11 critical vulnerabilities in Kiteworks' Core and gateway components. Shadowserver tracks nearly 400 internet-exposed Kiteworks instances, but does not identify how many are patched or are honeypots.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/)

---
Canonical: https://techandbusiness.org/newswire/aDkmMTWOb7q9eSsEM6hVf8
Published: 2026-10-01T15:12:04.752Z
Story chronology: 2026-10-01T13:51:08.000Z
Retrieved: 2026-10-01T18:17:55.516Z
Publisher: Tech & Business (techandbusiness.org)
