Kiteworks Patches Dozens of Critical Flaws After Shutdown Scare

Days after warning customers to shut systems down over a federal threat tip, Kiteworks disclosed dozens of new vulnerabilities, including a critical flaw letting attackers hijack admin accounts.

Illustration representing enterprise data security risks and protections for sensitive file sharing.
Data security risks and solutions graphic. Image: Kiteworks.

Kiteworks has disclosed dozens of new vulnerabilities across its enterprise file-sharing and email-security platform, including a critical, unauthenticated flaw that let attackers take over administrator accounts outright. The disclosure, published to the National Vulnerability Database on September 30, 2026, lands just days after Kiteworks told customers to shut their systems down over the weekend of September 25-27 following a "credible threat intelligence" warning from federal authorities. Kiteworks says every known issue is fixed in version 9.5.1, and administrators running the platform on-premises should patch immediately.

Key facts
  • Kiteworks asked customers to power down systems for roughly nine hours starting the evening of September 25, 2026, after a federal threat tip.
  • The shutdown recommendation was lifted September 27, 2026, with no confirmed compromise found.
  • On September 30, 2026, NVD published roughly 50 new Kiteworks CVEs, several rated critical, all fixed in version 9.5.0 or 9.5.1.
  • The worst, CVE-2026-102115 (CVSS 9.8), let an unauthenticated attacker who knew a user's email address reset that account's password, including admin accounts.
  • Kiteworks says it has no evidence any of the flaws were exploited before being fixed.

The September 25 shutdown advisory

Kiteworks is a private data network used by government agencies, defense contractors, banks, and healthcare organizations to move and secure sensitive files, including through its Email Protection Gateway and Secure Data Forms products. On September 25, 2026, the company published a precautionary shutdown advisory telling customers it had "received credible threat intelligence from federal intelligence authorities" suggesting a threat actor might try to target some Kiteworks deployments.

Rather than wait for an attack to surface, Kiteworks recommended a precautionary shutdown window of roughly nine hours, timed to local business hours, during which it said the threat was believed to be most acute. Customers running Kiteworks on their own infrastructure, including on-premises, AWS, or Azure deployments, were told to take their own systems offline; Kiteworks said it would shut down the environments it hosts on customers' behalf.

"We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach," Kiteworks Chief Information Security Officer Frank Balonis said in the company's advisory. By September 27, Kiteworks said continuous monitoring had turned up no abnormal activity, and hosted systems were brought back online. The company noted the warning did not extend to its separately branded subsidiaries, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder.

What the newly disclosed CVEs cover

Three days after the shutdown ended, the scale of the underlying problem became clear. On September 30, 2026, the National Vulnerability Database published a large batch of new Kiteworks CVE records, each one tracing back to a GitHub security advisory published by Kiteworks' own security team at github.com/kiteworks/security-advisories. Taken together, the batch spans the company's core platform, Email Protection Gateway, and Secure Data Forms (which includes the Advanced Forms feature), and covers a wide range of weakness types: SQL injection, server-side request forgery, OS command injection, stored cross-site scripting, privilege escalation, insecure deserialization, and missing authentication checks.

Kiteworks says every vulnerability in the batch is fixed in version 9.5.0, with a handful of forms-related issues requiring the follow-up 9.5.1 release. None of the CVEs in the batch currently appear on CISA's Known Exploited Vulnerabilities catalog, and Kiteworks has said it has no evidence of in-the-wild exploitation of the newly disclosed issues.

The breadth of the batch is unusual even by the standards of a mature enterprise product. Among the roughly 50 records, NVD lists five separate server-side request forgery flaws in Email Protection Gateway alone (CVE-2026-102095, CVE-2026-102102, CVE-2026-102103, CVE-2026-102104, and CVE-2026-102105), each stemming from the gateway fetching URLs found in message content without adequately restricting the destination — a pattern that could let a remote, unauthenticated sender trick the gateway into querying internal services or cloud metadata endpoints. Separately, CVE-2026-102106 describes an administrative service in Email Protection Gateway that "did not consistently enforce administrator authentication," letting an attacker who referenced a valid admin account create, modify, or delete internal users and managed domains, including deleting a domain in a way that could lock administrators out of the gateway entirely. A stored SQL injection in Core's administrative reporting feature (CVE-2026-102098) and a privilege-escalation path that let code running on one node of a clustered deployment execute commands on another node (CVE-2026-102120) round out the more serious entries.

The flaws to prioritize

With roughly 50 CVEs in a single disclosure, most enterprise security teams will want to triage. A handful stand out for requiring no authentication at all, or for handing an attacker a path to full administrative control.

CVE IDComponentCVSSIssueFixed in
CVE-2026-102115Core9.8 CriticalUnauthenticated password-reset flaw allows full account takeover, including admin accounts9.5.0
CVE-2026-102149Email Protection Gateway9.4 CriticalCertificate assignment flaw lets an attacker associate a certificate with another account9.5.0
CVE-2026-102147Core9.3 CriticalUnauthenticated stored cross-site scripting9.5.0
CVE-2026-102121Secure Data Forms (Advanced Forms)8.6 HighUnauthenticated form endpoint leaked the form owner's account profile and configuration data9.5.1
CVE-2026-102097Email Protection Gateway7.2 HighRemote code execution via an insufficiently validated admin configuration import9.5.0
CVE-2026-102096Core7.2 HighOS command injection via a crafted administrative configuration package9.5.0

CVE-2026-102115 is the one worth losing sleep over. According to the NVD record, Kiteworks Core "did not correctly validate a parameter submitted to the password reset workflow," meaning an unauthenticated attacker who simply knew a user's email address could reset that account's password without ever touching the emailed reset link, then log in as that user — including, NVD notes, when "the account holds administrative privileges." That combination of no authentication, no user interaction, and administrative impact is why the flaw carries a 9.8 CVSS base score in its CVE record. One caveat on the numbers: because the batch was published only on September 30, the severity scores in NVD are currently the ones supplied with the CVE records themselves rather than NVD's own independent analysis, which typically follows days or weeks later and can move a score up or down.

The Advanced Forms issue, CVE-2026-102121, is notable for a different reason: unlike most of the batch, which was fixed in 9.5.0, it required the follow-up 9.5.1 release — the exact build Kiteworks named in its shutdown advisory as the one in which "all known vulnerabilities are addressed." That makes 9.5.1, not 9.5.0, the floor for anyone running the forms component. NVD describes a form-rendering endpoint reachable without authentication that "returned more data than the form itself required," exposing a form owner's account profile and parts of the deployment's configuration, though not passwords or multi-factor secrets.

Who runs Kiteworks, and who's exposed

Kiteworks markets itself as a "private data network" for organizations that need to move highly sensitive files under strict compliance regimes: CMMC, FedRAMP, HIPAA, and similar frameworks common across defense, government, financial services, and healthcare. That customer base is exactly why a batch of pre-authentication, high-severity flaws in the platform matters well beyond the product itself — Email Protection Gateway and Core deployments are frequently exposed to receive mail and file transfers from outside the organization, which is the access an attacker would need for several of the flaws above.

Self-managed customers running Kiteworks on-premises, AWS, or Azure are responsible for applying the 9.5.0 and 9.5.1 updates themselves. Kiteworks-hosted customers should already be on a patched build, since the company controls those environments directly, but it is worth confirming with Kiteworks support rather than assuming.

Why this matters for regulated industries

Kiteworks positions itself specifically for organizations that must prove compliance with frameworks like CMMC, FedRAMP, and HIPAA — defense contractors, federal agencies, banks, and hospital systems among them. Those are exactly the organizations for which a breach involving Social Security numbers, financial records, or protected health information carries outsized regulatory and reputational consequences, and exactly the kind of organizations that tend to run secure file-transfer gateways facing the open internet so outside partners can send files in. That combination — a sensitive customer base and internet-facing components — is why unauthenticated, pre-login flaws like CVE-2026-102115 and the Email Protection Gateway SSRF cluster matter more here than a similarly rated bug in a purely internal tool would.

It is also why Kiteworks' own disclosure volume should be read as a mixed signal rather than a simple red flag. The company runs a public vulnerability disclosure program through Bugcrowd and credits outside researchers in many of its GitHub advisories, which is part of why so many issues surface at once rather than trickling out. A platform that attracts sustained outside scrutiny and pays for it tends to end up more secure over time than one that does not — but only for customers who actually apply the resulting patches promptly.

How to patch and what to check

Kiteworks' own guidance, repeated across each advisory in its GitHub security-advisories repository, is straightforward: upgrade to 9.5.0 at minimum, and to 9.5.1 to pick up the Advanced Forms and Secure Data Forms fixes. Administrators should treat this as an out-of-band emergency patch cycle rather than something to roll into a routine maintenance window, given how many of the flaws require no credentials and several affect internet-facing components like the Email Protection Gateway and public form endpoints.

Beyond applying the update itself, security teams should review authentication logs around password-reset activity for any accounts, especially administrative ones, for resets that the account owner does not recognize, and should audit which Secure Data Forms are published externally and what data those forms are configured to collect. Organizations that cannot patch immediately should, at minimum, restrict network access to administrative interfaces and the appliance setup interface, since several of the lower-severity issues in the same batch specifically depend on those interfaces being reachable.

This kind of emergency, out-of-band patch cycle has become a familiar pattern across enterprise infrastructure this year — see Pandromeda's coverage of the Cisco Catalyst SD-WAN Manager flaw and the critical WordPress RCE bug for two recent examples of vendors pushing urgent fixes outside their normal release cycle.

Part of a longer pattern

This is not Kiteworks' first large vulnerability disclosure of 2026. Earlier in the year, the company fixed a separate set of issues including a stored cross-site scripting flaw in Email Protection Gateway's configuration interface (CVE-2026-28272, fixed in version 9.2.0), an OS command injection flaw that let authenticated users redirect command output to overwrite system files (CVE-2026-28269, also fixed in 9.2.0), a session-management bug that let disabled accounts keep active sessions (CVE-2026-29092, fixed in 9.2.1), and an access-control flaw in Kiteworks Core that let authenticated users reach content they should not have been able to see (CVE-2026-23514, fixed in 9.2.2). Each of those was disclosed through the same GitHub security-advisories channel and tracked in NVD, and none has appeared on CISA's exploited-vulnerabilities list.

The volume and recurrence of these disclosures reflect a broader reality for secure file-transfer and managed file-transfer platforms generally: because they sit at the boundary between an organization's network and the outside world, and because they are built to handle highly sensitive data, they are a high-value target that draws sustained security research, both from Kiteworks' own team and from outside researchers credited in its advisories. That scrutiny is, in one sense, a healthy sign — but it also means administrators of this class of product need to treat patching as a continuous, not occasional, task. The same logic applies to other router and infrastructure fleets that have seen sustained attacker interest, as Pandromeda has covered with MikroTik's RouterOS devices.

What's next

Kiteworks has not said whether the September 25 threat warning was connected to any specific CVE in the September 30 batch, and the company's advisory language keeps the two events officially separate: the shutdown as a precaution against a reported threat, the CVE batch as the result of its own and third-party security research. What is clear is that any organization running a self-managed Kiteworks deployment that has not yet moved to 9.5.1 is running software with at least one unauthenticated, critical-severity hole in it. Expect Kiteworks to continue publishing advisories through its GitHub security-advisories repository as further research lands, and expect CISA and NVD to keep tracking each one under its own CVE as they are confirmed.

Frequently asked questions

Which Kiteworks version fixes the new vulnerabilities?

Version 9.5.0 fixes the bulk of the roughly 50 CVEs published on September 30, 2026, and version 9.5.1 adds fixes for the remaining Secure Data Forms and Advanced Forms issues, including CVE-2026-102121. Kiteworks says all known vulnerabilities are addressed in 9.5.1, so that is the version self-managed customers should be targeting.

Was Kiteworks actually breached in September 2026?

No breach has been confirmed. Kiteworks said the September 25 shutdown advisory was preventative, issued after federal intelligence authorities passed on credible threat intelligence, and that it had no indication that Kiteworks or customer systems had been compromised. The shutdown recommendation was lifted on September 27 after monitoring showed no abnormal activity.

What is CVE-2026-102115?

It is the most severe flaw in the batch, carrying a CVSS base score of 9.8. Kiteworks Core did not correctly validate a parameter in the password reset workflow, so an unauthenticated attacker who knew a user's email address could reset that account's password without the emailed reset link and then log in as that user, including accounts with administrative privileges. It is fixed in version 9.5.0.

Are any Kiteworks vulnerabilities being exploited in the wild?

There is no public evidence of exploitation. None of the Kiteworks CVEs, including the September 30 batch and the earlier 2026 disclosures, currently appear in CISA's Known Exploited Vulnerabilities catalog, and Kiteworks has said it has no indication the newly disclosed flaws were exploited.

Do Kiteworks-hosted customers need to take action?

Customers whose environments Kiteworks hosts should already be running a patched build, because the company controls and updates those deployments directly. Organizations running Kiteworks themselves on-premises or on AWS or Azure are responsible for applying 9.5.0 and 9.5.1, and should confirm their current version rather than assume they are covered.

Where does Kiteworks publish its security advisories?

Kiteworks publishes advisories through its own GitHub organization at github.com/kiteworks/security-advisories, and each advisory is mirrored into the National Vulnerability Database under its CVE identifier. Both are primary sources administrators can check for affected versions and fix releases.

Sources

More on Kiteworks →KiteworksEnterprise securityVulnerabilitiesPatch managementFile transfer security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all