CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Kiteworks Email Protection Gateway, authentication bypass (CVSS 9.4), fixed in 9.5.1

cve · CVE-2026-102149 single-source

Coverage
1
first 2026-09-26 → last 2026-10-02
Latest activity
2026-10-02
Kiteworks warned of an imminent attack; its 2026-09-30 advisories now include an unauthenticated root-level…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance · regions: europe, switzerland
Sources cited
17
8 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-102149, newest first. Check the date before acting on an older one.

  • Upgrade every Kiteworks deployment to 9.5.1 or later (the Email Protection Gateway needs at least 9.4.1 for CVE-2026-54154), and ask Kiteworks Support in writing whether the flaw it found during the shutdown needs customer-side action on self-hosted instances.
    2026-09-26CVE-2026-54154 +7

Defender insights

What each entry about CVE-2026-102149 tells a defender to do, newest first.

2026-09-26HIGHKiteworks warned of an imminent attack; its 2026-09-30 advisories now include an unauthenticated root-level code-execution chain in the mail gateway

Story timeline

  1. 2026-09-26Kiteworks (formerly Accellion) tells customers worldwide to shut down after 'credible' law-enforcement intelligence of an imminent attack, then publishes fixes including an unauthenticated chain to root in its Email Protection Gateway (CVE-2026-54154, CVSS 10.0)
    active-threatsKiteworks warned of an imminent attack; its 2026-09-30 advisories now include an unauthenticated root-level code-execution chain in the mail gateway
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • Privilege EscalationExploitation for Privilege Escalation

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning · ATT&CK page ↗

Entries about Kiteworks Email Protection Gateway, authentication bypass (CVSS 9.4), fixed in 9.5.1 (1)

2026-09-26 · view entry permalink →

HIGHCVE-2026-54154 +7updatedNATOB2

Kiteworks (formerly Accellion) tells customers worldwide to shut down after 'credible' law-enforcement intelligence of an imminent attack, then publishes fixes including an unauthenticated chain to root in its Email Protection Gateway (CVE-2026-54154, CVSS 10.0)

Kiteworks, a secure managed-file-transfer and confidential-communications platform rebranded from Accellion in 2021 and marketed to government agencies, financial institutions and enterprises, emailed customers worldwide on 2026-09-25 urging a precautionary shutdown of every Kiteworks system, staggered by timezone; press coverage put it at six hours, and the Central European window falls 04:00–10:00 CEST on Saturday 2026-09-26, a timezone Switzerland shares (Heise Online, 2026-09-25; TechCrunch, 2026-09-25). Kiteworks' own page gives the recommended window as nine hours (Kiteworks, 2026-09-27). CISO Frank Balonis wrote to customers, in an email obtained by Heise Online, that the company "received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend" (Heise Online, 2026-09-25), and recommended shutting systems down even where they are not directly internet-facing, since the possible access route is unconfirmed. No CVE was known for the threat behind the warning (The Record, 2026-09-25), and Kiteworks stated plainly it was "not aware of any compromise of Kiteworks systems" and that "all known vulnerabilities are addressed in our current release, 9.5.1" (BleepingComputer, 2026-09-25); the advisory is preventative, not a confirmed-breach response. Researcher Kevin Beaumont's Shodan search found at least a thousand internet-facing Kiteworks instances, though TechCrunch notes the count is likely an overcount of actually-affected customer systems (TechCrunch, 2026-09-25), and watchTowr's Jake Knott called the request itself unusual: "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch" (The Record, 2026-09-25).

The precedent class is exactly the one that matters for public-sector defenders: BleepingComputer notes that the Clop extortion gang "has a long history of targeting enterprise platforms in data-theft attacks," naming Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer as past victims of that pattern (BleepingComputer, 2026-09-25); no actor has been named or confirmed for this specific warning by Kiteworks, the FBI, or CISA. Kiteworks itself was formerly Accellion, whose FTA product was the subject of exactly this kind of zero-day mass exploitation in December 2020, when a Clop-linked group stole data from dozens of high-profile organizations (The Record, 2026-09-25).

We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours

Kiteworks CISO Frank Balonis, via Heise Online

We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach

All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version.

Kiteworks, statement to BleepingComputer

There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch.

Jake Knott, watchTowr, via The Record (Recorded Future News)

As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online.

Kiteworks 2026-09-27

We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach.

Frank Balonis, CISO, Kiteworks

"An attacker can exploit a vulnerability in Kiteworks Advanced Forms to carry out an unspecified attack." # translated from German

BSI CERT-Bund (WID-SEC-2026-3602) 2026-09-27

During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base.

Kiteworks developed and deployed a fix during the window, applied an additional protective layer across all environments, and has no indication the vulnerability was ever exploited.

Kiteworks 2026-09-27

A remote attacker may be able to execute arbitrary code with root privileges.

Kiteworks (security advisory, Email Protection Gateway) 2026-09-30

The flaw affects all Kiteworks Email Protection Gateway releases before 9.4.1 and is now patched in versions 9.4.1 or later.

Kiteworks has yet to share additional details on the fixed vulnerability and has not yet assigned a CVE ID for easy tracking.

BleepingComputer 2026-09-25
Updaterun 2026-09-29T0405Z-intelprioritytagsaffected_productssourcesevidencesourcing_noteactionsbody

Kiteworks' own press release states the recommended shutdown window was nine hours, while press coverage of the initial advisory reported six; the vendor's own page is the more authoritative figure, and neither the press coverage nor Kiteworks' later statement explains the difference. Kiteworks updated its own press release on 2026-09-27 to state the shutdown recommendation is lifted: "As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online" (Kiteworks, 2026-09-27). CISO Frank Balonis reiterated the company found no evidence of compromise: "We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach" (Kiteworks, 2026-09-27). Germany's BSI published advisory WID-SEC-2026-3602 on 2026-09-27, citing the Kiteworks press release as its source and naming the vulnerable component for the first time: "An attacker can exploit a vulnerability in Kiteworks Advanced Forms to carry out an unspecified attack" (translated from German) (BSI CERT-Bund, 2026-09-27), listing Advanced Forms versions below 9.5.1 as affected and fixed in 9.5.1; NCSC Switzerland's Cyber Security Hub advisory was updated the same day with the lifted-shutdown status. No CVE has been assigned to date, and the BSI record carries no vulnerability-class (CWE) description beyond "unspecified attack": genuinely thin technical detail from the vendor side even now.

Updaterun 2026-09-30T0404Z-intelsummarysourcesevidenceactionsbody

Kiteworks's own release, dated 2026-09-28, reports the outcome of the shutdown: the threat window "passed without incident", and the company has no indication that any Kiteworks or customer system was compromised (Kiteworks, 2026-09-28). It adds that its engineering and security activity during the shutdown led to the discovery of "a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base", that Kiteworks developed and deployed a fix during the window and applied an additional protective layer across all environments, and that it has no indication the vulnerability was ever exploited; all other Kiteworks products were unaffected (Kiteworks, 2026-09-28). The release names no component and no CVE; whether it is the Advanced Forms flaw that BSI listed on 2026-09-27 is not stated. The vendor's own statements are the only source for the discovery, the fix and the absence of exploitation, and customers with questions are pointed to Kiteworks Technical Support (Kiteworks, 2026-09-28).

Updaterun 2026-10-02T0404Z-inteltitleheadlinesummaryprioritytagstechniquesaffected_productscvessourcesevidenceactionsverificationentitiessourcing_notebody

On 2026-09-30 Kiteworks published GitHub security advisories for Email Protection Gateway, Core and Secure Data Forms. The most severe, CVE-2026-54154, affects all Email Protection Gateway versions before 9.4.1: a remote attacker may be able to execute arbitrary code with root privileges, with a CVSS 3.1 vector of network, low complexity, no privileges and no user interaction, and Kiteworks credits three researchers who reported it through its YesWeHack bug-bounty programme (Kiteworks, 2026-09-30). BleepingComputer, quoting the advisory, describes input-handling flaws in publicly reachable endpoints that potentially allowed unauthenticated code execution and, by chaining local weaknesses, escalation to root, and lists path traversal, code injection and missing authentication as the chain (BleepingComputer, 2026-10-01). Three further advisories rated CVSS 9.8 describe network-reachable account takeovers that need no privileges or user interaction and are fixed in 9.5.0: two in Email Protection Gateway, CVE-2026-85065 (Kiteworks, 2026-09-30) and CVE-2026-85066 (Kiteworks, 2026-09-30), and one in Core, CVE-2026-102115 (Kiteworks, 2026-09-30). BleepingComputer counts 11 critical fixes in Core and Email Protection Gateway beyond the root chain (BleepingComputer, 2026-10-01). Further fixes in 9.5.1 include an Email Protection Gateway account takeover, CVE-2026-102149, reachable over the network without authentication (Kiteworks, 2026-09-30); a Core account takeover to administrative access through an injection flaw, CVE-2026-102147, that needs user interaction (Kiteworks, 2026-09-30); a Core command execution flaw for administrators, CVE-2026-102142 (Kiteworks, 2026-09-30); and a Secure Data Forms security bypass, CVE-2026-102150, in versions 9.3.0 up to before 9.5.1 (Kiteworks, 2026-09-30).

BleepingComputer reports Kiteworks fixed 126 vulnerabilities in the same cycle and that Shadowserver tracks nearly 400 internet-exposed Kiteworks instances, with no patch-state information (BleepingComputer, 2026-10-01). No advisory states exploitation, and no source ties any of these flaws to the one Kiteworks found during the shutdown, which BleepingComputer says Kiteworks still has not detailed or assigned a CVE (BleepingComputer, 2026-10-01).

threat26 Sep 04:04Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • github.com8 (47%)
  • bleepingcomputer.com2 (12%)
  • kiteworks.com2 (12%)
  • heise.de1 (6%)
  • security-hub.ncsc.admin.ch1 (6%)
  • techcrunch.com1 (6%)
  • therecord.media1 (6%)
  • wid.cert-bund.de1 (6%)

External references

NVD · cve.org · CISA KEV

All cited sources (17)