Threat reportVulnerabilityTL-2026-2902
Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)
Kiteworks 9.5.1 Patches 126 Vulnerabilities Including (TL-2026-2902), also tracked as Kiteworks 9.5.1 security update, is a critical-severity software vulnerability scored CVSS 9.4, first published 2026-10-02. It has no confirmed attribution, affects Kiteworks Kiteworks Core, references 9 CVEs (CVE-2026-102141, CVE-2026-102142, CVE-2026-102143), maps to 4 MITRE ATT&CK techniques (T1059, T1078, T1190), and is covered by 9 detection rules and 7 indicators of compromise.
- CVSS
- 9.4/10Critical
- CVEs
- 9Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 7Indicators of compromise
Key facts for TL-2026-2902
- Threat ID
- TL-2026-2902
- Also known as
- Kiteworks 9.5.1 security update, GHSA-xgh2-fgj6-w93r, GHSA-c9w5-4frw-7wqq
- Severity
- CRITICAL
- CVSS
- 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, legal, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
How Kiteworks 9.5.1 Patches 126 Vulnerabilities Including works
Kiteworks released version 9.5.1 (9.5.0 for one Secure Data Forms flaw) fixing 126 vulnerabilities across Kiteworks Core, Email Protection Gateway (EPG) and Secure Data Forms (SDF), led by two critical account-takeover flaws. The release followed a vendor-advised precautionary shutdown on 'credible threat intelligence' from federal authorities; Kiteworks reports no confirmed compromise.
On 2026-09-30 Kiteworks published GitHub security advisories (kiteworks/security-advisories) for a large batch of flaws fixed in release 9.5.1; Cyber Security News reported on 2026-10-02 that the update addresses 126 vulnerabilities in total (the advisory repository spans about 15 pages; ten advisories were reviewed individually for this record). Kiteworks is a managed file transfer / secure content-governance platform used for sensitive data exchange.
Critical: (1) GHSA-xgh2-fgj6-w93r / CVE-2026-102147, Kiteworks Core account takeover, CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), CWE-79; the advisory describes an injection flaw that lets a remote attacker obtain administrative access, and credits wlayzz, Icare, Supr4s and truff via the YesWeHack bug bounty. (2) GHSA-c9w5-4frw-7wqq / CVE-2026-102149, Email Protection Gateway account takeover, CVSS 9.4 (AV:N/AC:L/PR:N/UI:N), CWE-306 and CWE-639; unauthenticated remote attackers can hijack user accounts through insufficient authorization checks.
High: GHSA-gmgg-7xhc-75f9 / CVE-2026-102142, Core arbitrary command execution by an administrator through template-engine injection (CVSS 7.2, CWE-1336); GHSA-3p9g-jh62-8f89 / CVE-2026-102143, EPG unauthenticated file write to the appliance (CVSS 7.5, CWE-306, CWE-434); GHSA-vwvw-rp3m-rm37 / CVE-2026-102150, SDF authentication bypass allowing limited internal operations (CVSS 7.2, CWE-306, CWE-522; affects 9.3.0 through 9.5.0); GHSA-9x72-vqwh-v4hv, SDF unauthenticated data modification via injection (CVSS 8.6, CWE-89, affects 9.2.0 through 9.4.1, fixed in 9.5.0, no CVE assigned).
Moderate: GHSA-m39v-w8fv-gf3m / CVE-2026-102141, Core privilege escalation where an attacker with root on one node can execute code on another node via a path-handling issue (CVSS 6.7, CWE-73, CWE-269); GHSA-h97r-j99c-q8xc / CVE-2026-102145, Core administrator CRLF injection / SSRF reaching internal network resources (CVSS 6.6, CWE-93, CWE-918); GHSA-5pgq-v8g2-rg2f / CVE-2026-102146, EPG administrator arbitrary file write (CVSS 6.5, CWE-73, CWE-1336); GHSA-wwhf-5862-rjxq / CVE-2026-102144, EPG unauthenticated denial of service (CVSS 5.3, CWE-306, CWE-400). Where the news article and the GitHub advisories disagree on severity (it lists GHSA-5pgq-v8g2-rg2f and GHSA-m39v-w8fv-gf3m as High), the GitHub advisories are used here.
Context: on 2026-09-25 Kiteworks told customers that it had received credible threat intelligence from federal intelligence authorities that a threat actor may attempt to target some Kiteworks systems, and recommended a precautionary weekend shutdown window (nine hours per the vendor notice; The Record reports six hours). Self-managed customers had to shut down themselves; Kiteworks-hosted systems were handled by the vendor. The vendor stated it had no indication of compromise and lifted the recommendation on 2026-09-27. The Record and Hendry Adrian coverage drew parallels to the December 2020 Clop zero-day campaign against Accellion (Kiteworks' predecessor product line); no actor is named, no exploitation is confirmed, and no CVE-to-campaign link has been published. watchTowr's Jake Knott noted that no CVE, patch or technical detail was available at the time of the shutdown request. Whether the 126-fix release relates to the threat-intelligence warning is not established by the sources.
Defender guidance: upgrade Core and EPG to 9.5.1 or later (SDF to 9.5.1; 9.5.0 minimum for GHSA-9x72), review account and administrator activity on exposed instances, restrict administrator interface exposure, and hunt for unexpected file writes on the EPG appliance and anomalous administrator sessions.
MITRE ATT&CK techniques used in TL-2026-2902
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Impact
Affected products and versions in Kiteworks 9.5.1 Patches 126 Vulnerabilities Including
- Kiteworks — Kiteworks Core
Vulnerable versions: all versions before 9.5.1
Fixed in: 9.5.1 - Kiteworks — Kiteworks Email Protection Gateway
Vulnerable versions: all versions before 9.5.1
Fixed in: 9.5.1 - Kiteworks — Kiteworks Secure Data Forms
Vulnerable versions: 9.2.0 through 9.4.1 (GHSA-9x72-vqwh-v4hv); 9.3.0 through 9.5.0 (GHSA-vwvw-rp3m-rm37)
Fixed in: 9.5.0 (GHSA-9x72-vqwh-v4hv); 9.5.1 (GHSA-vwvw-rp3m-rm37)
Remediation for Kiteworks 9.5.1 Patches 126 Vulnerabilities Including
Patches
- Kiteworks 9.5.1 (Core, Email Protection Gateway, Secure Data Forms)
- Kiteworks Secure Data Forms 9.5.0 (GHSA-9x72-vqwh-v4hv)
Immediate actions
- Upgrade Kiteworks Core and Email Protection Gateway to 9.5.1 or later
- Upgrade Kiteworks Secure Data Forms to 9.5.1 (9.5.0 is the minimum for GHSA-9x72-vqwh-v4hv)
- Audit administrator and user account activity on internet-exposed Kiteworks instances
Workarounds
- No vendor workaround published; the vendor's 2026-09-25 advisory recommended a temporary precautionary shutdown of self-managed systems (since lifted on 2026-09-27)
Longer-term hardening
- Enforce MFA and strong authentication controls for Kiteworks administrator and user accounts
- Restrict network exposure of administrator interfaces and the Email Protection Gateway
- Monitor the kiteworks/security-advisories repository; the vendor discloses details for up to 12 months after a patch
CVEs associated with Kiteworks 9.5.1 Patches 126 Vulnerabilities Including
CVE-2026-102141, CVE-2026-102142, CVE-2026-102143, CVE-2026-102144, CVE-2026-102145, CVE-2026-102146, CVE-2026-102147, CVE-2026-102149, CVE-2026-102150
Weaknesses (CWE) in Kiteworks 9.5.1 Patches 126 Vulnerabilities Including
CWE-79, CWE-89, CWE-93, CWE-73, CWE-269, CWE-306, CWE-400, CWE-434, CWE-522, CWE-639
Timeline of Kiteworks 9.5.1 Patches 126 Vulnerabilities Including
- Historical context cited by the press: the Clop group exploited a zero-day in Accellion's file transfer appliance (Kiteworks' predecessor product line) against organisations including the University of Colorado, Flagstar Bank, Bombardier and Kroger
- Kiteworks notifies customers that federal intelligence authorities (reported as FBI and CISA) warned a threat actor may target some Kiteworks systems, and recommends a precautionary weekend shutdown window; states 9.5.1 addresses all known vulnerabilities and that it has no indication of compromise
- The shutdown request is covered by the press; watchTowr notes no CVE, patch or technical detail is public. Reported window length differs (nine hours per vendor notice, six hours per The Record)
- Kiteworks lifts the precautionary shutdown recommendation for all customers
- Kiteworks publishes GitHub security advisories with CVE-2026-1021xx identifiers for Core, Email Protection Gateway and Secure Data Forms, including critical account takeover CVE-2026-102147 and CVE-2026-102149
- Cyber Security News reports Kiteworks patched 126 vulnerabilities in 9.5.1 (9.5.0 for Secure Data Forms); no exploitation documented
Sources cited for Kiteworks 9.5.1 Patches 126 Vulnerabilities Including
- Kiteworks Patches 126 Vulnerabilities in Massive Security Update
- Kiteworks Security Advisories Repository
- GHSA-xgh2-fgj6-w93r Kiteworks Core account takeover (CVE-2026-102147)
- GHSA-c9w5-4frw-7wqq Kiteworks Email Protection Gateway account takeover (CVE-2026-102149)
- GHSA-gmgg-7xhc-75f9 Kiteworks Core arbitrary code execution (CVE-2026-102142)
- GHSA-3p9g-jh62-8f89 Kiteworks Email Protection Gateway unauthorized file modification (CVE-2026-102143)
- GHSA-9x72-vqwh-v4hv Kiteworks Secure Data Forms unauthorized data modification
- Kiteworks Precautionary Shutdown Advisory
- Kiteworks urges customers to stop using systems after warning from federal intelligence agencies (The Record)
- Kiteworks urges customers to stop using platform after warning from federal intelligence agencies (Hendry Adrian)
Detection coverage for TL-2026-2902
As of 2026-10-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2902 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.