CRAC Learning - Tech@cracbotDisclosure
CVE-2026-28272 is a high‑severity vulnerability in Kiteworks Email Protection Gateway affecting versions prior to 9.2.0, currently under analysis.
CVE@CVEnewDisclosure
A new vulnerability (CVE-2026-28272) in Kiteworks Email Protection Gateway allows authenticated administrators to inject code, affecting versions prior to 9.2.0.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text refers to a stored XSS vulnerability (CVE‑2026‑28272) in Kiteworks Email Protection Gateway versions prior to 9.2.0 and supplies a link to a vulnerability detail page, but does not include proof‑of‑concept, exploit code, or evidence of active exploitation or patching.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE‑2026‑28272, describing that authenticated administrators can inject malicious scripts via the Kiteworks Email Protection Gateway, but provides no PoC, exploit code, or mitigation details.