Kiteworks released security updates addressing 126 vulnerabilities across Kiteworks Core, Email Protection Gateway (EPG), and Secure Data Forms (SDF). The most serious flaws affect Core and EPG versions earlier than 9.5.1, including critical account-takeover vulnerabilities that could expose sensitive files, email workflows, sharing functions, and administrative capabilities. Core fixes also include arbitrary code execution, privilege escalation, and exposure of internal network resources; EPG and SDF fixes address unauthorized data modification, denial of service, and security-bypass issues.
The Canadian Centre for Cyber Security issued advisory AV26-988 urging organizations to review Kiteworks advisories and apply available updates. Administrators should upgrade affected deployments to 9.5.1 or later where applicable, identify internet-facing instances, and investigate suspicious account activity or indications of unauthorized access, particularly before remediation changes alter available evidence.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-988, directing administrators to consult Kiteworks security advisories and apply available updates.
Kiteworks Core, Email Protection Gateway, and Secure Data Forms were identified as affected by unspecified vulnerabilities. Affected releases include versions before 9.5.0 and/or 9.5.1, depending on the product.
Kiteworks released a broad security update for 126 vulnerabilities across its secure data-transfer platform and associated applications. The fixes include critical account-takeover flaws in Core and Email Protection Gateway, arbitrary code execution and privilege escalation in Core, and data-modification, denial-of-service, and security-bypass issues in Email Protection Gateway and Secure Data Forms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecryptika.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.