BlackTree Security · Infrastructure · Automation · AI

Kiteworks Email Gateway Flaw Could Give Attackers Root Without a Login

Kiteworks says CVE-2026-54154 can let a remote attacker execute code on its Email Protection Gateway without an account. Reaching root requires further local weaknesses to be chained. Every EPG release before 9.4.1 is affected, and the vendor directs customers to install 9.4.1 or later.

What the advisory establishes

The CVSS 10.0 advisory was published on 30 September 2026, without a public time. The advisory does not say whether the flaw has been exploited. It supplies no indicators or proof of concept.

Treat the appliance as a separate exposure decision

Response guidance, not an exploitation claim: NIST’s incident-response recommendations support evidence preservation, containment and recovery verification. The following is BlackTree’s application of that general framework, not a vendor indicator list.

Record the deployed product, installed build, internet-facing interfaces and administrative access. Check each appliance individually, rather than assuming an update to one component proves the whole estate is current.

Apply the named upgrade. If maintenance cannot happen immediately, reduce external reach to the minimum required. Preserve network, authentication and appliance records first, especially where retention is short.

After patching, review administrative accounts, configuration changes, unexpected files and outbound connections. Correlate local evidence with identity-provider, firewall, proxy and central logs. A healthy mail flow does not prove the earlier trust boundary held.

Do not merge this with the September shutdown

BlackTree’s earlier article, Kiteworks Pulled the Plug and Found a Critical Flaw, concerns the precautionary shutdown and a separate Advanced Forms issue. Nothing in the EPG advisory ties this flaw to that shutdown. Sharing a vendor name is not proof that two vulnerabilities are the same incident.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *