
CVE-2026-28271: Kiteworks / SSRF CVE-2026-28270: Kiteworks / Unrestricted Upload of File with Dangerous Type CVE-2026-28269: Kiteworks / Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') with @truffzor
Post summary
The text enumerates three new Kiteworks CVEs, specifying the nature of each vulnerability (SSRF, dangerous file upload, OS Command Injection), but provides no details on exploitation, patches, or PoC.


