Kiteworks patches maximum severity code injection vulnerability in Email Protection Gateway
126 vulnerabilities addressed in latest security updates; remote code execution risk identified

Key Takeaways
- Kiteworks released security updates addressing 126 vulnerabilities.
- A maximum severity code injection flaw affects the Email Protection Gateway (EPG).
- The vulnerability could allow remote code execution on affected systems.
- Users should apply the latest updates immediately to mitigate the risk.
- The status of active exploitation is not specified, but risk is high until patched.
Quick answers
- What happened?
- Kiteworks has released security updates to address 126 vulnerabilities, including a maximum severity code injection flaw affecting the Email Protection Gateway (EPG) security solution. The vulnerability could allow remote code execution on affected systems. Users are advised to apply the latest updates immediately.
- Which products are affected?
- Email Protection Gateway
- What should defenders do?
- Apply the latest security updates released by Kiteworks for the Email Protection Gateway. Monitor for additional advisories and ensure systems are running the patched firmware or software version.
Kiteworks, a secure file-sharing software company, has released security updates to address 126 vulnerabilities, including a maximum severity flaw affecting its Email Protection Gateway (EPG) security solution. The code injection vulnerability in the EPG could allow remote code execution, potentially enabling attackers to run arbitrary code on affected systems. The company did not specify the status of active exploitation, but given the maximum severity rating, the risk of active exploitation is considered high until systems are patched. The Email Protection Gateway is globally deployed, and users should apply the latest security updates to mitigate the identified risk. No specific CVE identifiers were listed in the source report.
Security Details
Maximum severity code injection vulnerability in Email Protection Gateway (EPG) could allow remote code execution. Specific CVE identifiers were not provided in the source.
Affected products
Email Protection Gateway
Mitigation
Apply the latest security updates released by Kiteworks for the Email Protection Gateway. Monitor for additional advisories and ensure systems are running the patched firmware or software version.
Sources
BleepingComputer
Kiteworks patches max severity code injection vulnerability
Oct 1, 2026 · 13:51
Original link
Related Security News

Dell Patches Two Maximum Severity Vulnerabilities in Container Storage Modules
Dell has released security updates to patch two maximum severity vulnerabilities in the Container Storage Modules (CSM) component. The flaws affect Dell enterprise storage arrays connected to Kubernetes environments and could allow attackers with network access to achieve remote code execution and admin-level privileges. Patches have been released and admins are urged to apply them as soon as possible.
CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.