Enterprise file-sharing gateways exposed by maximum-severity flaw
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 2nd, 2026.
Organizations using Kiteworks Email Protection Gateway face remote takeover if exposed appliances remain below version 9.4.1. Kiteworks released updates covering 126 vulnerabilities. The most serious is a maximum-severity chain that requires no login or user interaction and can let an attacker execute code before gaining full administrative control of the appliance.
The wider update also fixes 11 critical weaknesses involving authentication, account takeover and access control. That matters because the gateway connects email, file sharing, managed transfers, APIs and web forms. A compromise could therefore place several sensitive workflows at risk rather than affecting only one service.
Nearly 400 Kiteworks instances were tracked as exposed to the internet, although their patch status was unknown. Leaders should confirm who owns and maintains every deployed gateway. Defenders should inventory versions, limit public access and investigate exposed appliances before assuming an upgrade has removed every risk. Upgrade Email Protection Gateway to 9.4.1 or later and investigate exposed systems for compromise. Consolidated security platforms can also concentrate risk when their management boundaries fail.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.