# Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection Gateway (CVE-2026-102147, CVE-2026-102149)

> Kiteworks released version 9.5.1 (9.5.0 for one Secure Data Forms flaw) fixing 126 vulnerabilities across Kiteworks Core, Email Protection Gateway (EPG) and Secure Data Forms (SDF), led by two critical account-takeover flaws. The release followed a vendor-advised precautionary shutdown on 'credible threat intelligence' from federal authorities; Kiteworks reports no confirmed compromise.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2902
- **ID:** TL-2026-2902
- **Severity:** CRITICAL (CVSS 9.4)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 7 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-102141, CVE-2026-102142, CVE-2026-102143, CVE-2026-102144, CVE-2026-102145, CVE-2026-102146, CVE-2026-102147, CVE-2026-102149, CVE-2026-102150

## Description

On 2026-09-30 Kiteworks published GitHub security advisories (kiteworks/security-advisories) for a large batch of flaws fixed in release 9.5.1; Cyber Security News reported on 2026-10-02 that the update addresses 126 vulnerabilities in total (the advisory repository spans about 15 pages; ten advisories were reviewed individually for this record). Kiteworks is a managed file transfer / secure content-governance platform used for sensitive data exchange.

Critical: (1) GHSA-xgh2-fgj6-w93r / CVE-2026-102147, Kiteworks Core account takeover, CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N), CWE-79; the advisory describes an injection flaw that lets a remote attacker obtain administrative access, and credits wlayzz, Icare, Supr4s and truff via the YesWeHack bug bounty. (2) GHSA-c9w5-4frw-7wqq / CVE-2026-102149, Email Protection Gateway account takeover, CVSS 9.4 (AV:N/AC:L/PR:N/UI:N), CWE-306 and CWE-639; unauthenticated remote attackers can hijack user accounts through insufficient authorization checks.

High: GHSA-gmgg-7xhc-75f9 / CVE-2026-102142, Core arbitrary command execution by an administrator through template-engine injection (CVSS 7.2, CWE-1336); GHSA-3p9g-jh62-8f89 / CVE-2026-102143, EPG unauthenticated file write to the appliance (CVSS 7.5, CWE-306, CWE-434); GHSA-vwvw-rp3m-rm37 / CVE-2026-102150, SDF authentication bypass allowing limited internal operations (CVSS 7.2, CWE-306, CWE-522; affects 9.3.0 through 9.5.0); GHSA-9x72-vqwh-v4hv, SDF unauthenticated data modification via injection (CVSS 8.6, CWE-89, affects 9.2.0 through 9.4.1, fixed in 9.5.0, no CVE assigned).

Moderate: GHSA-m39v-w8fv-gf3m / CVE-2026-102141, Core privilege escalation where an attacker with root on one node can execute code on another node via a path-handling issue (CVSS 6.7, CWE-73, CWE-269); GHSA-h97r-j99c-q8xc / CVE-2026-102145, Core administrator CRLF injection / SSRF reaching internal network resources (CVSS 6.6, CWE-93, CWE-918); GHSA-5pgq-v8g2-rg2f / CVE-2026-102146, EPG administrator arbitrary file write (CVSS 6.5, CWE-73, CWE-1336); GHSA-wwhf-5862-rjxq / CVE-2026-102144, EPG unauthenticated denial of service (CVSS 5.3, CWE-306, CWE-400). Where the news article and the GitHub advisories disagree on severity (it lists GHSA-5pgq-v8g2-rg2f and GHSA-m39v-w8fv-gf3m as High), the GitHub advisories are used here.

Context: on 2026-09-25 Kiteworks told customers that it had received credible threat intelligence from federal intelligence authorities that a threat actor may attempt to target some Kiteworks systems, and recommended a precautionary weekend shutdown window (nine hours per the vendor notice; The Record reports six hours). Self-managed customers had to shut down themselves; Kiteworks-hosted systems were handled by the vendor. The vendor stated it had no indication of compromise and lifted the recommendation on 2026-09-27. The Record and Hendry Adrian coverage drew parallels to the December 2020 Clop zero-day campaign against Accellion (Kiteworks' predecessor product line); no actor is named, no exploitation is confirmed, and no CVE-to-campaign link has been published. watchTowr's Jake Knott noted that no CVE, patch or technical detail was available at the time of the shutdown request. Whether the 126-fix release relates to the threat-intelligence warning is not established by the sources.

Defender guidance: upgrade Core and EPG to 9.5.1 or later (SDF to 9.5.1; 9.5.0 minimum for GHSA-9x72), review account and administrator activity on exposed instances, restrict administrator interface exposure, and hunt for unexpected file writes on the EPG appliance and anomalous administrator sessions.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1565.001 Stored Data Manipulation

## Sources

- [Kiteworks Patches 126 Vulnerabilities in Massive Security Update](https://cybersecuritynews.com/kiteworks-patches-vulnerabilities/)
- [Kiteworks Security Advisories Repository](https://github.com/kiteworks/security-advisories/security)
- [GHSA-xgh2-fgj6-w93r Kiteworks Core account takeover (CVE-2026-102147)](https://github.com/kiteworks/security-advisories/security/advisories/GHSA-xgh2-fgj6-w93r)
- [GHSA-c9w5-4frw-7wqq Kiteworks Email Protection Gateway account takeover (CVE-2026-102149)](https://github.com/kiteworks/security-advisories/security/advisories/GHSA-c9w5-4frw-7wqq)
- [GHSA-gmgg-7xhc-75f9 Kiteworks Core arbitrary code execution (CVE-2026-102142)](https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gmgg-7xhc-75f9)
- [GHSA-3p9g-jh62-8f89 Kiteworks Email Protection Gateway unauthorized file modification (CVE-2026-102143)](https://github.com/kiteworks/security-advisories/security/advisories/GHSA-3p9g-jh62-8f89)
- [GHSA-9x72-vqwh-v4hv Kiteworks Secure Data Forms unauthorized data modification](https://github.com/kiteworks/security-advisories/security/advisories/GHSA-9x72-vqwh-v4hv)
- [Kiteworks Precautionary Shutdown Advisory](https://www.kiteworks.com/?p=254398)
- [Kiteworks urges customers to stop using systems after warning from federal intelligence agencies (The Record)](https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident)
- [Kiteworks urges customers to stop using platform after warning from federal intelligence agencies (Hendry Adrian)](https://www.hendryadrian.com/?p=114112)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2902
