Kiteworks Core
product · product:kiteworks-core single-source
Action items (1)
Do-now tasks recorded on the entries about Kiteworks Core, newest first. Check the date before acting on an older one.
- Upgrade every Kiteworks deployment to 9.5.1 or later (the Email Protection Gateway needs at least 9.4.1 for CVE-2026-54154), and ask Kiteworks Support in writing whether the flaw it found during the shutdown needs customer-side action on self-hosted instances.2026-09-26CVE-2026-54154 +7
Defender insights
What each entry about Kiteworks Core tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- Privilege EscalationExploitation for Privilege Escalation
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning · ATT&CK page ↗
Entries about Kiteworks Core (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cl0p×1
- Kiteworks×1
- Kiteworks Advanced Forms×1
- Kiteworks Core, account takeover (CVSS 9.8), fixed in 9.5.0×1
- Kiteworks Email Protection Gateway×1
- Kiteworks Email Protection Gateway, account takeover (CVSS 9.8), fixed in 9.5.0×1
- Kiteworks Email Protection Gateway, account takeover (CVSS 9.8), fixed in 9.5.0×1
- Kiteworks Email Protection Gateway, authentication bypass (CVSS 9.4), fixed in 9.5.1×1
Where this entity is cited
Source distribution
- github.com8 (47%)
- bleepingcomputer.com2 (12%)
- kiteworks.com2 (12%)
- heise.de1 (6%)
- security-hub.ncsc.admin.ch1 (6%)
- techcrunch.com1 (6%)
- therecord.media1 (6%)
- wid.cert-bund.de1 (6%)
All cited sources (17)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/kiteworks-patches-max-severity-email-protection-gateway-code-injection-vulnerability/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
- github.comKiteworks (security advisory, Email Protection Gateway)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-5xhq-9wq3-rvj6
- github.comKiteworks (security advisory, Email Protection Gateway)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c9w5-4frw-7wqq
- github.comKiteworks (security advisory, Core)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gmgg-7xhc-75f9
- github.comKiteworks (security advisory, Email Protection Gateway)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-h669-jj53-h764
- github.comKiteworks (security advisory, Core)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-q76w-qv9j-q639
- github.comKiteworks (security advisory, Email Protection Gateway)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-rwpq-5xfv-54pv
- github.comKiteworks (security advisory, Secure Data Forms)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-vwvw-rp3m-rm37
- github.comKiteworks (security advisory, Core)https://github.com/kiteworks/security-advisories/security/advisories/GHSA-xgh2-fgj6-w93r
- heise.deHeise Onlinehttps://www.heise.de/en/news/Imminent-Zero-Day-Attack-KiteWorks-Urges-Customers-to-Shut-Down-Servers-11466375.html
- kiteworks.comKiteworkshttps://www.kiteworks.com/company/press-releases/kiteworks-precautionary-shutdown-advisory/
- kiteworks.comKiteworkshttps://www.kiteworks.com/company/press-releases/kiteworks-restores-systems-credible-threat/
- security-hub.ncsc.admin.chNCSC Switzerland, Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12985
- techcrunch.comTechCrunchhttps://techcrunch.com/2026/09/25/kiteworks-urges-customers-to-shut-down-their-servers-amid-imminent-threat-of-cyberattack/
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
- wid.cert-bund.deBSI CERT-Bund (WID-SEC-2026-3602)https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3602