Kiteworks published 125 advisories. None says which one, if any, is the shutdown flaw
Kiteworks published 125 advisories in 22 minutes, led by a 10.0 flaw in its Email Protection Gateway that is fixed in 9.4.1. Its shutdown statement had already called 9.5.1 current, and nothing published says which advisory, if any, is the flaw found that weekend.
By Parminder Kumar Sharma · · 18 min read

125 advisories in two bursts, and no fix above 9.5.1
On 30 September 2026 Kiteworks published 125 security advisories on its GitHub register. They went out in two bursts: 50 between 16:38:48 and 16:40:45 UTC, then 75 between 16:58:14 and 17:00:59, which is 17:38 to 18:00 in the UK. The register went from 23 advisories to 148. The highest score belongs to CVE-2026-54154, a CVSS 10.0 code injection chain in the Email Protection Gateway (EPG), and its advisory names 9.4.1 as the fixed version.
On 25 September Kiteworks called 9.5.1 its "current release". No advisory in the 125 names a fixed version above 9.5.1. So the flaw reported on 1 October as max severity was fixed in a version numbered below one that was already current when Kiteworks asked customers to shut down.
That is the question brief 165 left open: does a release finally supply the CVE, score and fixed version for the flaw Kiteworks said it found during the shutdown? For the 10.0 flaw, yes. For the shutdown flaw, no record says it is the 10.0 flaw, and none says it is any other. The earlier briefs are Kiteworks told customers to shut down for six hours. Its own press release says nine, twice and Kiteworks says it fixed a critical flaw. It has published no CVE, score or version. Neither is restated here.
What that does not establish. It does not establish that the 10.0 flaw is unrelated to the shutdown. A version number is not a release date, and I could not find release dates for 9.4.1, 9.5.0 or 9.5.1 on any public Kiteworks page. It does not establish that the shutdown flaw is missing from the 125: it may be rated below critical, shipped without a new version number, or fixed only in the systems Kiteworks hosts. It does not establish exploitation, or its absence. What it does establish is narrower. Five days after the shutdown notice, the one public place that could say which advisory, if any, is the shutdown flaw does not say.
What brief 165 asked for, and what arrived
Brief 165 named three things a defender needs to look a flaw up: a CVE, a score and a fixed version. Here is where each stands for the two flaws in play. Kiteworks's register, the CVE Program and the NVD were all read on 1 October 2026 between about 19:10 and 19:15 BST, and any of these states can change within hours. The advisories came 2 days after the 28 September release that first reported the fix, 3 days after the 27 September notice lifting the recommendation, and 5 days after the shutdown advice of 25 September.
Brief 165's three missing items, checked on 1 October 2026 against Kiteworks's advisory register, the CVE Program and the NVD.
| Item | The 10.0 EPG flaw | The shutdown flaw |
|---|---|---|
| CVE ID | CVE-2026-54154, in the Kiteworks advisory | None attached by any record I could read |
| Score, and who gave it | CVSS 3.1 base 10.0, from Kiteworks in its own advisory | None. The 28 September release says only "critical" |
| Fixed version | 9.4.1 or later | None. No advisory names a version above 9.5.1 |
| Product | Email Protection Gateway, every version before 9.4.1 | A capability enabled for under 1% of customers; on 27 September, self-hosted Advanced Forms |
| Found by | Three researchers, through Kiteworks's bug bounty on YesWeHack | The shutdown response, with federal intelligence authorities, per Kiteworks |
| CVE record published | Not yet: the CVE Program and the NVD returned nothing | No ID to look up |
The 10.0 flaw, field by field
The advisory, GHSA-5xhq-9wq3-rvj6, was published from Kiteworks's own repository at 16:38:48 UTC, the first of the 125. It says a combination of input-handling flaws in "publicly reachable endpoints" of the EPG "potentially allowed" an unauthenticated remote attacker to run code and, by chaining further local weaknesses, to reach full administrative (root) control of the appliance. It lists three weakness classes: path traversal (CWE-22), code injection (CWE-94) and missing authentication (CWE-306). The remediation is one line: upgrade to 9.4.1 or later. It states no workaround.
CVE-2026-54154, GHSA-5xhq-9wq3-rvj6, read from Kiteworks's GitHub repository on 1 October 2026.
| Item | Stated | Not stated |
|---|---|---|
| Identity | CVE-2026-54154; EPG versions before 9.4.1 | Whether a CVE record exists: the CVE Program says it does not, and the NVD returns no result |
| Score | CVSS 3.1 base 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | Any NVD or CISA score; which boundary the changed scope crosses |
| Fix | Upgrade to 9.4.1 or later | A workaround; the release date of 9.4.1 |
| Reach | Unauthenticated, over the network, no user interaction | Hosted against self-managed instances; when the flaw entered the code |
| Credit | wlayzz, icare and truff, through YesWeHack | When it was reported, and whether before 25 September |
| Exploitation | Nothing either way | Any telemetry, from Kiteworks or anyone else |
Who assigned the score. In the only place it appears, Kiteworks did. The NVD has no record to hold a score, and CISA's Vulnrichment programme (CISA-ADP) has added nothing because the CVE Program has no record to add to. For comparison, 60 of the register's 124 CVE IDs do have CVE Program records, plus one more, CVE-2026-102125. All 61 name the CISA U.S. Civilian Government CVE Numbering Authority (CNA, short name cisa-cg) as assigner, and all 61 were reserved at 17:39 UTC on 28 September. Of the 60 that can be compared with Kiteworks's register, 59 match on score and vector. The exception, CVE-2026-102110, matches on score (5.9) but not on vector. None of the 61 is the 10.0 flaw. One neutral observation: Kiteworks's bounty page ties rewards to the CVSS score and the asset's value, so the company that scores an advisory is also the one that pays by the score. That is ordinary practice, and it is the reason an independent score is worth waiting for.
What "max severity" means. The 10.0 is a CVSS v3.1 base score. Its vector differs from a 9.8 by one letter: S:C, scope changed. Compute the same vector with scope unchanged and the impact and exploitability terms sum to 9.76, which rounds up to 9.8. With scope changed the impact term rises to 6.05, and 1.08 times the sum is 10.73, capped at 10.0. Both are critical and both call for the same action, so the extra 0.2 is a judgement about a security boundary, and the advisory does not say which boundary. Kiteworks's own bug bounty page says that, for its scoring, remote code execution on its own and escalation to root on its own are not a scope change. That does not show the 10.0 is wrong. The page governs bounty rewards, and the advisory may rest on a boundary it does not describe. It shows that "max severity" is the output of a rule the advisory leaves unstated.
Is it the flaw from the shutdown?
Kiteworks has not said. Its 28 September release says the response to the threat intelligence "led to the discovery" of a previously unknown critical vulnerability in a capability enabled for under 1% of customers, and that "All other Kiteworks products were unaffected". Set that beside the advisory.
Kiteworks's 27 and 28 September statements, with CyberScoop's report of them, set beside the 30 September advisory for CVE-2026-54154.
| Test | Shutdown flaw | CVE-2026-54154 |
|---|---|---|
| Where it sits | A capability enabled for under 1% of customers; self-hosted Advanced Forms named on 27 September | Email Protection Gateway, every version before 9.4.1 |
| Who found it | The response to the threat intelligence, with federal intelligence authorities | Three bug bounty researchers, credited by name |
| Fixed in | Fixed "during the window"; no version or date | 9.4.1, below the 9.5.1 called current on 25 September |
| Rated | Called "critical"; no score | CVSS 10.0, scored by Kiteworks |
| Other products | Kiteworks says all others were unaffected; CyberScoop lists email encryption among them | The EPG, which Kiteworks describes as encrypting, routing and blocking mail |
Four published facts point away from the two being the same flaw. None proves it.
First, the number. The advisory says "9.4.1 or later", which includes the 9.5.1 Kiteworks called current on 25 September. A flaw fixed "during the window" should not carry an older number, unless Kiteworks backported it or its numbering is not chronological, and no release dates are published. Second, the product: the 27 September notice sent Advanced Forms customers to support, not EPG customers. Third, the finders: the shutdown flaw came out of the response, the 10.0 flaw from outside researchers, and no document says when their report arrived. Fourth, the statement that all other products were unaffected.
Where the shutdown flaw could be hiding. If it is among the 125, it is not rated critical in the product Kiteworks's own bounty page calls "SDF, aka Advanced Forms". The register's 28 Secure Data Forms advisories top out at 8.6 and none reaches 9.0. Five are rated high. Two concern Advanced Forms interfaces reachable without authentication: CVE-2026-102121 (8.6), which returned more data than a published form needs, and CVE-2026-102150 (7.2). Both are fixed in 9.5.1. One, GHSA-9x72-vqwh-v4hv (8.6, fixed in 9.5.0), is a SQL injection and is the only one of the 125 with no CVE ID. Nothing links any of the three to the shutdown, and I am not saying any of them is the flaw. I am saying that if one is, "critical" in the 28 September release did not mean a CVSS score of 9.0 or above.
The word "critical" already has more than one meaning in Kiteworks's own documents. Its bounty page says the company considers a flaw critical "only if it poses an immediate threat to a significantly large percentage of our customer base", in a passage about flaws that need administrator rights. The 28 September release calls the shutdown flaw critical while confining it to under 1% of customers. The two can be reconciled by different definitions. Neither document says which one the release used.
The other 124: fixes that predate the advisories
Take away the headline and the batch is a disclosure of fixes that already existed by version number. All 125 advisories name a fixed version between 9.2.1 and 9.5.1. Fifty, or 40%, name a version below 9.5.0, and the five for 9.2.1 were published 189 days after an advisory of 25 March 2026 had already listed 9.2.1 as a fixed version. BleepingComputer says Kiteworks "released security updates" for 126 vulnerabilities. On the register, a closer reading is advisories for flaws whose fixes had shipped in versions up to 9.5.1, which by Kiteworks's own account was current on 25 September. That is a derived reading, not Kiteworks's wording.
One claim is at least consistent with the register. On 25 September Kiteworks said it had "accounted for all known vulnerabilities" in 9.5.1. Nothing in the register needs a higher number. That is checkable in a way the shutdown flaw is not.
By Kiteworks's own ratings the 125 split into 12 critical (9.6%), 49 high (39.2%), 52 medium (41.6%) and 12 low (9.6%). Critical or high together are 61, or 48.8%. Before 30 September the register held 23 advisories, none critical, the highest 8.8. The weight is in two products.
The 125 advisories of 30 September by product tag and Kiteworks's own severity rating, counted from the register.
| Product | Advisories | Critical | High |
|---|---|---|---|
| Core | 66 | 2 | 30 |
| Email Protection Gateway | 28 | 10 | 12 |
| Secure Data Forms (Advanced Forms) | 28 | 0 | 5 |
| MFT | 3 | 0 | 2 |
| All | 125 | 12 | 49 |
Ten of the 12 critical advisories are in the EPG, which is 10 of its 28, or 36%. They are the ones to read first.
The 12 critical advisories of 30 September, from Kiteworks's register. Classes are Kiteworks's wording, shortened.
| CVE | Product and class | Score | Fixed in |
|---|---|---|---|
| CVE-2026-54154 | EPG, code injection chain | 10.0 | 9.4.1 |
| CVE-2026-102115 | Core, password reset bypass | 9.8 | 9.5.0 |
| CVE-2026-85066 | EPG, password reset bypass | 9.8 | 9.5.0 |
| CVE-2026-85065 | EPG, authentication bypass | 9.8 | 9.5.0 |
| CVE-2026-102149 | EPG, certificate assignment | 9.4 | 9.5.1 |
| CVE-2026-102147 | Core, stored XSS to admin takeover | 9.3 | 9.5.1 |
| CVE-2026-102106 | EPG, admin authentication bypass | 9.1 | 9.5.0 |
| CVE-2026-102105 | EPG, SSRF | 9.1 | 9.5.0 |
| CVE-2026-102104 | EPG, SSRF | 9.1 | 9.5.0 |
| CVE-2026-102103 | EPG, SSRF | 9.1 | 9.5.0 |
| CVE-2026-102102 | EPG, SSRF | 9.1 | 9.5.0 |
| CVE-2026-102095 | EPG, SSRF | 9.1 | 9.5.0 |
The five EPG server-side request forgeries are worth a sentence, because they show what the product name hides. According to the advisories, each is triggered while the gateway handles a message: rendering content that references external resources, checking certificate status, fetching a revocation list, fetching an issuer certificate, or fetching URLs in the message itself. The last one, CVE-2026-102095, is described as reaching internal services and cloud instance metadata endpoints.
How many, and how findable. BleepingComputer says 126 vulnerabilities. The register holds 125 advisories: 124 with a CVE ID and one without. The CVE Program separately holds CVE-2026-102125, a Core document conversion sandbox escape rated 8.8, whose cited Kiteworks advisory, GHSA-58j2-hj9r-c258, returned "not found" when I requested it. The 125 advisories plus that one record make 126, which would reconcile BleepingComputer's figure. The article does not say how it counted, so that is my inference.
At about 19:10 BST on 1 October the CVE Program held records for 60 of the register's 124 CVE IDs, all in the range CVE-2026-102089 to CVE-2026-102150. The other 64 returned no record, including the 10.0 and both EPG 9.8 authentication bypasses, CVE-2026-85065 and CVE-2026-85066. The NVD returned 51 Kiteworks CVEs published in September, all "Awaiting Analysis". A scanner or ticket rule keyed to CVE records cannot see what is not yet in the list. The records that do exist cite a CISA advisory file, va-26-274-01, which was not in CISA's repository when I looked.
Who found them. 82 of the 125 carry an acknowledgement: 74 name YesWeHack, 7 name Bugcrowd, and one thanks "an undisclosed customer" for a finding during a penetration test. None credits a government body. Four handles (icare, truff, wlayzz and supr4s) account for the credit on 61 of the 125, and the three credited on the 10.0 flaw are named together on 51. 43 carry no acknowledgement at all, including 7 of the 10 critical EPG advisories, so for those the register does not say who found them. No advisory text mentions the shutdown, CISA, the FBI or intelligence authorities; I searched all 148. The press releases name "federal intelligence authorities" without naming an agency, and CyberScoop reports that Kiteworks declined to say which. The bounty page's update note records the launch of a new public programme in September 2026 and shows 183 reports. It does not say how long any report waited for a fix.
Four names that are not controls
Each friendly name in this story stands in for a fact that is missing.
"Max severity." A score somebody assigned, with a scope metric doing the last 0.2. Here Kiteworks assigned it, in its own advisory, and no independent scorer has confirmed it.
"Security updates." A disclosure date. For 50 of the 125 the fix had existed for months by version number, and for all 125 it had existed, by number, since before the shutdown. A reader who sees "patched" on 1 October should ask patched when, and in which version.
"Email Protection Gateway." The name describes what the product does for your mail. It says nothing about what the product exposes. A gateway exists to process messages written by strangers, and in these advisories that processing is the attack surface. The advisories describe unauthenticated routes to administrator accounts, managed domains, certificates and, in the 10.0 case, the appliance itself. Until it is patched, an email protection product is a network service on your mail path.
"Precautionary shutdown." A pause, not a fix. A shutdown defends against an attack that arrives while you are off, which brief 126 set out. The flaws in these advisories were as reachable on Monday as on Friday for anyone below the fixed version. The control is the version, and the version can be checked.
What is said about exploitation, as at 1 October
Every row is time-stamped, because each could be overtaken within hours.
Exploitation and exposure evidence for the 147 CVE IDs in Kiteworks's register, read on 1 October 2026.
| Question | On the record | Not stated |
|---|---|---|
| Is any in CISA's KEV catalogue? | No. KEV version 2026.09.30, still the newest at 19:33 BST on 1 October, holds only four Accellion FTA entries from 2021 | Any later addition |
| What does CISA-ADP say? | Exploitation "none" on 59 of the 61 CVE Program records, written 13:13 to 15:14 UTC on 1 October | Anything on CVE-2026-54154, which has no record to enrich |
| What do the advisories say? | Nothing about exploitation in any of the 125 | Whether anyone has tried |
| What does Kiteworks say? | 28 September: "no indication" the shutdown flaw was exploited | Whether that covers the EPG flaw, or systems customers host |
| How many are exposed? | BleepingComputer cites Shadowserver for nearly 400 internet-facing Kiteworks instances | A split by product: the Shadowserver chart carries one Kiteworks fingerprint |
What to do about it, in order
Written for a UK organisation that runs Kiteworks, or depends on a supplier that does. The UK items rest on NCSC and ICO guidance, linked in the sources.
Take this with you
In the order worth doing
- List every Kiteworks component you run or rely on (Core, Email Protection Gateway, Secure Data Forms or Advanced Forms, MFT), its version, and whether Kiteworks hosts it or you do. For hosted instances, ask Kiteworks in writing which version each runs and since when, because the advisories do not say.
- Move every self-managed component to 9.5.1 or later, the highest fixed version named in any of the 125. Do the Email Protection Gateway first: it holds 10 of the 12 critical advisories, and the 10.0 flaw affects every version before 9.4.1. Check each component's version separately.
- Until it is patched, shrink the exposure. This is general hardening, not a Kiteworks workaround, because the advisories state none: restrict who can reach the gateway's administrative and web interfaces, and restrict its outbound connections to internal services and cloud metadata addresses.
- Enforce multi-factor authentication on every account, administrators first. The advisory for CVE-2026-85065 says accounts with an enforced second factor were not affected, and CVE-2026-102115 concerns accounts with locally stored passwords.
- Preserve logs from the gateway and Core hosts for the whole period you ran a version before 9.5.1, not only the weekend of 26 and 27 September. Look for administrator accounts or managed domains created, changed or deleted without a change record, mail routing or policy changes, certificate assignments you did not make, password resets on administrator accounts, unexpected files on the appliance, and outbound connections from the gateway to internal hosts or cloud metadata addresses. These are consequences the advisories describe, not a statement that any occurred.
- If a gateway ran a version before 9.4.1 while reachable from the internet and you cannot rule out access, treat the appliance as untrusted. My judgement, not Kiteworks's advice: rebuild it after upgrading rather than cleaning it, and treat keys and certificates it held as exposed.
- If the systems are in Cyber Essentials scope, note that the NCSC requirement counts 14 days from release of the update, not from the advisory, for fixes the vendor calls critical or high or that score 7 or above. 61 of the 125 meet that test on Kiteworks's own ratings. Fourteen days from 30 September ends on 14 October, but for fixes released earlier the clock started earlier, and Kiteworks has published no release dates. Ask your assessor how to evidence the date.
- If personal data passed through a gateway you cannot clear, decide now who may declare awareness. The ICO says a reportable personal data breach goes to it within 72 hours of becoming aware of it, where feasible.
- Write to Kiteworks and keep the reply: which advisory, if any, is the flaw found during the shutdown; the fix identifier if it is not in the register; the release dates of 9.4.1, 9.5.0 and 9.5.1; and whether a CVE will follow for GHSA-9x72-vqwh-v4hv and for CVE-2026-102125.
- Do not let your scanner define done. 64 of the 124 register CVE IDs, including the 10.0, had no CVE Program record on 1 October, so a tool keyed to CVE records may report nothing. Track by version, and re-check the CVE Program, NVD and CISA KEV for these IDs weekly.
- Mark the risk register entry remediated only when you hold version evidence for every instance.
The question this leaves
Kiteworks has now done, for one flaw, what brief 165 asked: a CVE, a score, a fixed version and named finders, in an advisory anyone can read. It has not done it, or has done it without saying so, for the flaw it said it found during the weekend shutdown. From outside, those two cases look the same, and that is the gap.
So the question, for any supplier that tells you it fixed something critical and later publishes a long list: which line on that list is the one it told you about, who in your organisation asks, and what do you do if the answer is that it is not on the list?
Sources
- PrimaryThe advisory for CVE-2026-54154, read in full on the page and through the GitHub API, used for the description, the CVSS 3.1 10.0 vector, the CWE classes, the fixed version 9.4.1, the credit and the publication timeKiteworks on GitHubaccessed 2026-10-01
- PrimaryThe vendor's advisory register, all 148 advisories read through the GitHub API (cursor pagination), used for every count, severity, fixed version, publication time, credit and keyword search in the articleKiteworks on GitHubaccessed 2026-10-01
- PrimaryThe 28 September 2026 press release, re-read in full, used for the previously unknown critical vulnerability, the under 1% scope, the fix during the window and the statement that all other products were unaffectedKiteworksaccessed 2026-10-01
- PrimaryThe 25 September release with the 27 September notice, re-read in full, used for the current release 9.5.1 statement and the Advanced Forms noticeKiteworksaccessed 2026-10-01
- PrimaryKiteworks's public bug bounty programme page, read in full, used for the product aliases (SDF, aka Advanced Forms), the definition of critical, the scope changed rules and the programme launch noteYesWeHackaccessed 2026-10-01
- PrimaryThe Email Protection Gateway product page, used for what the vendor says the product does with inbound and outbound mailKiteworksaccessed 2026-10-01
- PrimaryThe CVE Services API record for CVE-2026-54154, which returned CVE_RECORD_DNE, and the 124 sibling IDs queried the same way, used for what is and is not publishedCVE Programaccessed 2026-10-01
- PrimaryThe NVD API for CVE-2026-54154 (zero results) and a Kiteworks keyword search (51 CVEs published in September 2026, all Awaiting Analysis, from the CISA CNA)NIST National Vulnerability Databaseaccessed 2026-10-01
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.09.30, used to confirm that none of the 147 CVE IDs and no Kiteworks entry newer than 2021 is listedCISAaccessed 2026-10-01
- PrimaryThe CISA CSAF directory that the CVE records cite as va-26-274-01, which was not present when readCISA on GitHubaccessed 2026-10-01
- PrimaryThe dashboard BleepingComputer cites, read to confirm it carries a single Kiteworks fingerprint and no split by productThe Shadowserver Foundationaccessed 2026-10-01
- PrimaryCyber Essentials: Requirements for IT Infrastructure v3.3, April 2026, used for the 14 days from release rule and the definition of critical or high riskNCSCaccessed 2026-10-01
- PrimaryPersonal data breaches: a guide, used for the 72 hours from becoming aware ruleInformation Commissioner's Officeaccessed 2026-10-01
- Reported byThe 1 October pointer article, read in a real browser because curl is refused, used for the 126 vulnerabilities, the 11 further critical flaws, the bug bounty attribution and the Shadowserver figureBleepingComputeraccessed 2026-10-01
- Reported byThe 29 September report, read directly, used for Kiteworks's list of unaffected products and its refusal to name the federal authoritiesCyberScoopaccessed 2026-10-01


