Kiteworks
Kiteworks Email Protection Gateway: vulnerabilities and CVEs
Kiteworks Email Protection Gateway has 19 published vulnerabilities, 19 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.
CVEs19
Last 12 months19
Critical7
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102149 | Critical (9.4) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the… |
| CVE-2026-102144 | Medium (5.3) | — | — | Sep 30, 2026 | A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of… |
| CVE-2026-102139 | Medium (6.5) | — | — | Sep 30, 2026 | An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of… |
| CVE-2026-102135 | Medium (6.6) | — | — | Sep 30, 2026 | On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially… |
| CVE-2026-102131 | High (7.2) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an… |
| CVE-2026-102130 | High (7.2) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could… |
| CVE-2026-102128 | High (7.5) | — | — | Sep 30, 2026 | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an… |
| CVE-2026-102127 | High (7) | — | — | Sep 30, 2026 | An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could… |
| CVE-2026-102116 | High (7.2) | — | — | Sep 30, 2026 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote… |
| CVE-2026-102108 | High (7.2) | — | — | Sep 30, 2026 | An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing… |
| CVE-2026-102106 | Critical (9.1) | — | — | Sep 30, 2026 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the… |
| CVE-2026-102105 | Critical (9.1) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote,… |
| CVE-2026-102104 | Critical (9.1) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote,… |
| CVE-2026-102103 | Critical (9.1) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote,… |
| CVE-2026-102102 | Critical (9.1) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote,… |
| CVE-2026-102097 | High (7.2) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not… |
| CVE-2026-102095 | Critical (9.1) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it… |
| CVE-2026-102094 | High (7.2) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An… |
| CVE-2026-102089 | High (7.2) | — | — | Sep 30, 2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the… |