Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102119 | HIGH | 7.2 | A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. … | Sep 30, 2026 |
| CVE-2026-102118 | HIGH | 7.8 | A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root … | Sep 30, 2026 |
| CVE-2026-102117 | HIGH | 7.2 | On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect … | Sep 30, 2026 |
| CVE-2026-102116 | HIGH | 7.2 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to … | Sep 30, 2026 |
| CVE-2026-102115 | CRITICAL | 9.8 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user … | Sep 30, 2026 |
| CVE-2026-102114 | HIGH | 7.2 | A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful … | Sep 30, 2026 |
| CVE-2026-102113 | HIGH | 7.8 | A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance … | Sep 30, 2026 |
| CVE-2026-102112 | HIGH | 7.8 | A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance … | Sep 30, 2026 |
| CVE-2026-102111 | MEDIUM | 4.9 | Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so … | Sep 30, 2026 |
| CVE-2026-102110 | MEDIUM | 5.9 | An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation … | Sep 30, 2026 |
| CVE-2026-102109 | HIGH | 7.1 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a … | Sep 30, 2026 |
| CVE-2026-102108 | HIGH | 7.2 | An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, … | Sep 30, 2026 |
| CVE-2026-102107 | MEDIUM | 4.6 | Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from … | Sep 30, 2026 |
| CVE-2026-102106 | CRITICAL | 9.1 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so … | Sep 30, 2026 |
| CVE-2026-102105 | CRITICAL | 9.1 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … | Sep 30, 2026 |
| CVE-2026-102104 | CRITICAL | 9.1 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … | Sep 30, 2026 |
| CVE-2026-102103 | CRITICAL | 9.1 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … | Sep 30, 2026 |
| CVE-2026-102102 | CRITICAL | 9.1 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway … | Sep 30, 2026 |
| CVE-2026-102101 | HIGH | 8.1 | Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data … | Sep 30, 2026 |
| CVE-2026-102100 | HIGH | 8.7 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user … | Sep 30, 2026 |
| CVE-2026-102099 | HIGH | 7.2 | Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature … | Sep 30, 2026 |
| CVE-2026-102098 | HIGH | 7.2 | Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated … | Sep 30, 2026 |
| CVE-2026-102097 | HIGH | 7.2 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose … | Sep 30, 2026 |
| CVE-2026-102096 | HIGH | 7.2 | Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not … | Sep 30, 2026 |
| CVE-2026-102095 | CRITICAL | 9.1 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the … | Sep 30, 2026 |