
CVE-2026-28271: Kiteworks / SSRF CVE-2026-28270: Kiteworks / Unrestricted Upload of File with Dangerous Type CVE-2026-28269: Kiteworks / Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') with @truffzor
Post summary
Three new Kiteworks CVEs are disclosed, covering SSRF, unrestricted file upload, and OS command injection.


