Kiteworks patches critical flaw in email gateway that let attackers seize root control
A chain of three bugs in the company's Email Protection Gateway handed unauthenticated outsiders a path to full appliance takeover. The fix is in version 9.4.1.

Key points
- Kiteworks' own advisory, GHSA-5xhq-9wq3-rvj6, confirms a remote attacker could run code as root on its Email Protection Gateway before version 9.4.1, meaning full control of the appliance without a password.
- The flaw, tracked as CVE-2026-54154, chains a path traversal bug, a code injection bug and a missing authentication check.
- All Email Protection Gateway versions before 9.4.1 are affected; 9.4.1 or later is the fix.
- Three researchers, wlayzz, icare and truff, reported it through Kiteworks' YesWeHack bug bounty.
- Kiteworks says it has seen no evidence of exploitation, and the broader patch set covers 126 issues across its product line.
Kiteworks has patched a critical hole in its Email Protection Gateway, a product that sits in front of corporate email to scan and secure sensitive attachments. The company's own security advisory says a remote attacker could run commands on the appliance with root privileges, the highest level of control a Linux system offers.
An outsider on the internet, with no account, could take the box over completely.
The bug is tracked as CVE-2026-54154. It affects every release of the Email Protection Gateway before 9.4.1. Upgrading to 9.4.1 or later closes it.
Kiteworks, formerly Accellion, sells file-sharing and secure email kit to banks and government agencies. The Accellion name may ring a bell for the wrong reason: its legacy File Transfer Appliance was ransacked in 2021, feeding breaches at Shell, Morgan Stanley and the Reserve Bank of New Zealand, among others. That history is why a maximum-severity bug in a Kiteworks edge appliance gets attention fast.
How bad is it?
Bad enough that Kiteworks told customers to shut their servers down before the fix was ready, as we reported on 1 October in Kiteworks Told Customers to Go Dark for Nine Hours After a Federal Warning. The advisory describes a chain of three weaknesses: path traversal, which lets an attacker reach files they shouldn't; code injection, which lets them slip commands into the program; and a missing authentication check, which means the gateway never asks who they are. Put together, those give arbitrary code execution on a public-facing box.
From there, Kiteworks says, additional local weaknesses let the attacker escalate to full root. No clicks, no credentials, no user interaction.
Who found it, and is it being exploited?
The researchers wlayzz, icare and truff reported the chain through Kiteworks' YesWeHack bug bounty programme. Kiteworks says it found no evidence of compromise or suspicious activity on hosted systems it brought back online this week.
That's a cleaner outcome than the Accellion episode five years ago, and it's the point of running a bounty: pay a researcher once, instead of paying a ransomware crew and your regulator later.
What should customers do now?
Patch to Email Protection Gateway 9.4.1 or newer, today if you haven't. If your appliance was exposed to the internet while unpatched, treat it as suspect: review logs, rotate any credentials or API keys the appliance held, and check for unexpected admin accounts. No login record proves an attacker tried, because the missing-authentication piece of this chain means the gateway never got that far.
The wider patch bundle covers 126 issues, including eleven other critical bugs across Kiteworks' Core and Email Protection Gateway components: authentication bypass, admin account takeover, stored cross-site scripting (a browser-side attack that runs attacker code in a logged-in user's session), improper access control and improper authentication. Any one of those is worth a maintenance window on its own.
| Item | Detail |
|---|---|
| CVE | CVE-2026-54154 |
| Advisory | GHSA-5xhq-9wq3-rvj6 |
| Affected | All Email Protection Gateway before 9.4.1 |
| Fixed in | 9.4.1 or later |
| Reported via | YesWeHack bug bounty |
| Total bugs in release | 126, including 11 other critical |
One honest note on the auth beat: multi-factor authentication wouldn't have saved anyone here. The missing authentication check meant the gateway never got to the login step. That's the uncomfortable thing about appliance bugs. The security control you bought is the thing the attacker walks through.



