Five numbers from Kiteworks's advisory register, read on the evening of 1 October. 10.0: the score on CVE-2026-54154, a code injection chain in the Email Protection Gateway reachable without logging in. 9.4.1: the version that fixes it. 9.5.1: the version Kiteworks called its current release on 25 September, the day it asked customers to shut down. 125: advisories published in 22 minutes on 30 September, none naming a fix newer than 9.5.1. 0: advisories that say which one, if any, is the flaw found during the shutdown.
🧮 The batch has 12 critical advisories (10 in the gateway, 2 in Core), and 61 of the 125 are critical or high. Credit goes to bug bounty researchers, on YesWeHack and Bugcrowd.
🔍 At 19:34 BST on 1 October, CVE[.]org had no record for CVE-2026-54154 and NVD returned nothing. 64 of the 124 CVE IDs in the batch had no CVE record. None of Kiteworks's CVE IDs is in CISA KEV (version 2026.09.30).
⚖️ By version number, the 10.0 flaw was fixed before the shutdown began. The flaw that justified the weekend still has no CVE, score or fixed version that any record attaches to it. Kiteworks may be right on every point; from outside, nobody can check.
🔑 If you run Kiteworks, have you asked your supplier which of the 125 advisories was the shutdown flaw?
Full briefing: https://www.pk-sharma.com/briefing/kiteworks-125-advisories-which-is-the-shutdown-flaw
#Kiteworks #CVE #VulnerabilityManagement #PatchManagement #EmailSecurity #CISA #KEV #InfoSec #CyberSecurity #CISO #ThreatIntel #SecOps #BlueTeam #UKTech