Threat reportVulnerabilityTL-2026-2902

Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)

criticalPATCHED

Kiteworks 9.5.1 Patches 126 Vulnerabilities Including (TL-2026-2902), also tracked as Kiteworks 9.5.1 security update, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-10-02. It has no confirmed attribution, affects Kiteworks Kiteworks Core, references 9 CVEs (CVE-2026-102141, CVE-2026-102142, CVE-2026-102143), maps to 4 MITRE ATT&CK techniques (T1059, T1078, T1190), and is covered by 9 detection rules and 7 indicators of compromise.

CVSS
9.4/10Critical
CVEs
9Referenced vulnerabilities
Techniques
4MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
7Indicators of compromise

Key facts for TL-2026-2902

Threat ID
TL-2026-2902
Also known as
Kiteworks 9.5.1 security update, GHSA-xgh2-fgj6-w93r, GHSA-c9w5-4frw-7wqq
Severity
CRITICAL
CVSS
9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, legal, enterprise
Target regions
Global
Detection rules
9
Indicators of compromise
7

How Kiteworks 9.5.1 Patches 126 Vulnerabilities Including works

Kiteworks released version 9.5.1 (9.5.0 for one Secure Data Forms flaw) fixing 126 vulnerabilities across Kiteworks Core, Email Protection Gateway (EPG) and Secure Data Forms (SDF), led by two critical account-takeover flaws. The release followed a vendor-advised precautionary shutdown on 'credible threat intelligence' from federal authorities; Kiteworks reports no confirmed compromise.

On 2026-09-30 Kiteworks published GitHub security advisories (kiteworks/security-advisories) for a large batch of flaws fixed in release 9.5.1; Cyber Security News reported on 2026-10-02 that the update addresses 126 vulnerabilities in total (the advisory repository spans about 15 pages; ten advisories were reviewed individually for this record). Kiteworks is a managed file transfer / secure content-governance platform used for sensitive data exchange.

Critical: (1) GHSA-xgh2-fgj6-w93r / CVE-2026-102147, Kiteworks Core account takeover, CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), CWE-79; the advisory describes an injection flaw that lets a remote attacker obtain administrative access, and credits wlayzz, Icare, Supr4s and truff via the YesWeHack bug bounty. (2) GHSA-c9w5-4frw-7wqq / CVE-2026-102149, Email Protection Gateway account takeover, CVSS 9.4 (AV:N/AC:L/PR:N/UI:N), CWE-306 and CWE-639; unauthenticated remote attackers can hijack user accounts through insufficient authorization checks.

High: GHSA-gmgg-7xhc-75f9 / CVE-2026-102142, Core arbitrary command execution by an administrator through template-engine injection (CVSS 7.2, CWE-1336); GHSA-3p9g-jh62-8f89 / CVE-2026-102143, EPG unauthenticated file write to the appliance (CVSS 7.5, CWE-306, CWE-434); GHSA-vwvw-rp3m-rm37 / CVE-2026-102150, SDF authentication bypass allowing limited internal operations (CVSS 7.2, CWE-306, CWE-522; affects 9.3.0 through 9.5.0); GHSA-9x72-vqwh-v4hv, SDF unauthenticated data modification via injection (CVSS 8.6, CWE-89, affects 9.2.0 through 9.4.1, fixed in 9.5.0, no CVE assigned).

Moderate: GHSA-m39v-w8fv-gf3m / CVE-2026-102141, Core privilege escalation where an attacker with root on one node can execute code on another node via a path-handling issue (CVSS 6.7, CWE-73, CWE-269); GHSA-h97r-j99c-q8xc / CVE-2026-102145, Core administrator CRLF injection / SSRF reaching internal network resources (CVSS 6.6, CWE-93, CWE-918); GHSA-5pgq-v8g2-rg2f / CVE-2026-102146, EPG administrator arbitrary file write (CVSS 6.5, CWE-73, CWE-1336); GHSA-wwhf-5862-rjxq / CVE-2026-102144, EPG unauthenticated denial of service (CVSS 5.3, CWE-306, CWE-400). Where the news article and the GitHub advisories disagree on severity (it lists GHSA-5pgq-v8g2-rg2f and GHSA-m39v-w8fv-gf3m as High), the GitHub advisories are used here.

Context: on 2026-09-25 Kiteworks told customers that it had received credible threat intelligence from federal intelligence authorities that a threat actor may attempt to target some Kiteworks systems, and recommended a precautionary weekend shutdown window (nine hours per the vendor notice; The Record reports six hours). Self-managed customers had to shut down themselves; Kiteworks-hosted systems were handled by the vendor. The vendor stated it had no indication of compromise and lifted the recommendation on 2026-09-27. The Record and Hendry Adrian coverage drew parallels to the December 2020 Clop zero-day campaign against Accellion (Kiteworks' predecessor product line); no actor is named, no exploitation is confirmed, and no CVE-to-campaign link has been published. watchTowr's Jake Knott noted that no CVE, patch or technical detail was available at the time of the shutdown request. Whether the 126-fix release relates to the threat-intelligence warning is not established by the sources.

Defender guidance: upgrade Core and EPG to 9.5.1 or later (SDF to 9.5.1; 9.5.0 minimum for GHSA-9x72), review account and administrator activity on exposed instances, restrict administrator interface exposure, and hunt for unexpected file writes on the EPG appliance and anomalous administrator sessions.

MITRE ATT&CK techniques used in TL-2026-2902

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Impact

T1565.001 Stored Data Manipulation

Affected products and versions in Kiteworks 9.5.1 Patches 126 Vulnerabilities Including

  • Kiteworks — Kiteworks Core
    Vulnerable versions: all versions before 9.5.1
    Fixed in: 9.5.1
  • Kiteworks — Kiteworks Email Protection Gateway
    Vulnerable versions: all versions before 9.5.1
    Fixed in: 9.5.1
  • Kiteworks — Kiteworks Secure Data Forms
    Vulnerable versions: 9.2.0 through 9.4.1 (GHSA-9x72-vqwh-v4hv); 9.3.0 through 9.5.0 (GHSA-vwvw-rp3m-rm37)
    Fixed in: 9.5.0 (GHSA-9x72-vqwh-v4hv); 9.5.1 (GHSA-vwvw-rp3m-rm37)

Remediation for Kiteworks 9.5.1 Patches 126 Vulnerabilities Including

Patches

  • Kiteworks 9.5.1 (Core, Email Protection Gateway, Secure Data Forms)
  • Kiteworks Secure Data Forms 9.5.0 (GHSA-9x72-vqwh-v4hv)

Immediate actions

  • Upgrade Kiteworks Core and Email Protection Gateway to 9.5.1 or later
  • Upgrade Kiteworks Secure Data Forms to 9.5.1 (9.5.0 is the minimum for GHSA-9x72-vqwh-v4hv)
  • Audit administrator and user account activity on internet-exposed Kiteworks instances

Workarounds

  • No vendor workaround published; the vendor's 2026-09-25 advisory recommended a temporary precautionary shutdown of self-managed systems (since lifted on 2026-09-27)

Longer-term hardening

  • Enforce MFA and strong authentication controls for Kiteworks administrator and user accounts
  • Restrict network exposure of administrator interfaces and the Email Protection Gateway
  • Monitor the kiteworks/security-advisories repository; the vendor discloses details for up to 12 months after a patch

CVEs associated with Kiteworks 9.5.1 Patches 126 Vulnerabilities Including

CVE-2026-102141, CVE-2026-102142, CVE-2026-102143, CVE-2026-102144, CVE-2026-102145, CVE-2026-102146, CVE-2026-102147, CVE-2026-102149, CVE-2026-102150

Weaknesses (CWE) in Kiteworks 9.5.1 Patches 126 Vulnerabilities Including

CWE-79, CWE-89, CWE-93, CWE-73, CWE-269, CWE-306, CWE-400, CWE-434, CWE-522, CWE-639

Timeline of Kiteworks 9.5.1 Patches 126 Vulnerabilities Including

  • Historical context cited by the press: the Clop group exploited a zero-day in Accellion's file transfer appliance (Kiteworks' predecessor product line) against organisations including the University of Colorado, Flagstar Bank, Bombardier and Kroger
  • Kiteworks notifies customers that federal intelligence authorities (reported as FBI and CISA) warned a threat actor may target some Kiteworks systems, and recommends a precautionary weekend shutdown window; states 9.5.1 addresses all known vulnerabilities and that it has no indication of compromise
  • The shutdown request is covered by the press; watchTowr notes no CVE, patch or technical detail is public. Reported window length differs (nine hours per vendor notice, six hours per The Record)
  • Kiteworks lifts the precautionary shutdown recommendation for all customers
  • Kiteworks publishes GitHub security advisories with CVE-2026-1021xx identifiers for Core, Email Protection Gateway and Secure Data Forms, including critical account takeover CVE-2026-102147 and CVE-2026-102149
  • Cyber Security News reports Kiteworks patched 126 vulnerabilities in 9.5.1 (9.5.0 for Secure Data Forms); no exploitation documented

Sources cited for Kiteworks 9.5.1 Patches 126 Vulnerabilities Including

Detection coverage for TL-2026-2902

As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2902 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
7 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats