CVE-2026-54154

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 5 mentions (2026-10-01); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-10-01: 5Mentions · 2026-10-02: 110-0110-02
Referenced assets3 URLs
Full discourse6 posts
  • Cybersecurity News Everyday@TweetThreatNews

    Kiteworks patched 126 vulnerabilities, including CVE-2026-54154 in Email Protection Gateway before 9.4.1. The flaw could enable unauthenticated remote code execution and root takeover. #Kiteworks #CVE202654154 #EPG https://www.hendryadrian.com/kiteworks-patches-max-severity-code-injection-vulnerability/

    01000212
    4.9K followersView on X
  • TwitGri@TwitGri

    ⚠️ Kiteworks : CVE-2026-54154 (CVSS 10) permet une RCE sans authentification sur Email Protection Gateway <9.4.1, avec prise de contrôle root possible. Kiteworks publie le correctif : mettez à jour vers 9.4.1+ sans attendre. #Cyber #Kiteworks

    0001052
    37 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers chaining path traversal and code injection to gain root control of Kiteworks Email Protection Gateway through CVE-2026-54154. With administrative access, threat actors could pivot across the private content network and establish persistent backdoors. Runtime segmentation helps contain such post-compromise lateral movement across enterprise infrastructure. #ZeroDay #CloudSecurity 🔗 Read the full report: https://aviatrix.ai/threat-research-center/kiteworks-patches-max-severity-code-injection-vulnerability-cve-2026-54154

    0000047
    2.0K followersView on X
  • P.K. Sharma@_pksharma

    Five numbers from Kiteworks's advisory register, read on the evening of 1 October. 10.0: the score on CVE-2026-54154, a code injection chain in the Email Protection Gateway reachable without logging in. 9.4.1: the version that fixes it. 9.5.1: the version Kiteworks called its current release on 25 September, the day it asked customers to shut down. 125: advisories published in 22 minutes on 30 September, none naming a fix newer than 9.5.1. 0: advisories that say which one, if any, is the flaw found during the shutdown. 🧮 The batch has 12 critical advisories (10 in the gateway, 2 in Core), and 61 of the 125 are critical or high. Credit goes to bug bounty researchers, on YesWeHack and Bugcrowd. 🔍 At 19:34 BST on 1 October, CVE[.]org had no record for CVE-2026-54154 and NVD returned nothing. 64 of the 124 CVE IDs in the batch had no CVE record. None of Kiteworks's CVE IDs is in CISA KEV (version 2026.09.30). ⚖️ By version number, the 10.0 flaw was fixed before the shutdown began. The flaw that justified the weekend still has no CVE, score or fixed version that any record attaches to it. Kiteworks may be right on every point; from outside, nobody can check. 🔑 If you run Kiteworks, have you asked your supplier which of the 125 advisories was the shutdown flaw? Full briefing: https://www.pk-sharma.com/briefing/kiteworks-125-advisories-which-is-the-shutdown-flaw #Kiteworks #CVE #VulnerabilityManagement #PatchManagement #EmailSecurity #CISA #KEV #InfoSec #CyberSecurity #CISO #ThreatIntel #SecOps #BlueTeam #UKTech

    0000036
    191 followersView on X
  • Xavier Rivera@XavierRiveraX

    Kiteworks EPG: max-severity code injection, CVE-2026-54154. Unauth RCE chain (path traversal + code injection + missing auth). No user click needed. Patch is 9.4.1+. 126 vulns in the same release, 11 critical. Ex-Accellion gear on email/MFT edges should move first.

    0000058
    600 followersView on X
  • MadeItHappen@MadeItHappenX

    @BleepinComputer CVE-2026-54154: unauth RCE on Kiteworks EPG via path traversal+injection. Patch all EPG before 9.4.1 to 9.4.1+; same drop has 126 fixes. Shadowserver still ~400 exposed. — Mr. Mackey, Cybersecurity https://t.co/weSllL6HrB

    0000078
    268 followersView on X

Explore more