Kiteworks Email Protection Gateway

22 known vulnerabilities in Kiteworks Email Protection Gateway, 7 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102149 CVSS 9.4 critical Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an…
  • CVE-2026-102146 CVSS 6.5 medium An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with…
  • CVE-2026-102144 CVSS 5.3 medium A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger…
  • CVE-2026-102143 CVSS 7.5 high An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an…
  • CVE-2026-102139 CVSS 6.5 medium An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the…
  • CVE-2026-102135 CVSS 6.6 medium On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted…
  • CVE-2026-102131 CVSS 7.2 high Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they…
  • CVE-2026-102130 CVSS 7.2 high Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to…
  • CVE-2026-102128 CVSS 7.5 high An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of…
  • CVE-2026-102127 CVSS 7.0 high An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default…
  • CVE-2026-102119 CVSS 7.2 high A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to…
  • CVE-2026-102116 CVSS 7.2 high -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended…
  • CVE-2026-102108 CVSS 7.2 high An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management…
  • CVE-2026-102106 CVSS 9.1 critical Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email…
  • CVE-2026-102105 CVSS 9.1 critical Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery…
  • CVE-2026-102104 CVSS 9.1 critical Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery…
  • CVE-2026-102103 CVSS 9.1 critical Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery…
  • CVE-2026-102102 CVSS 9.1 critical Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery…
  • CVE-2026-102097 CVSS 7.2 high Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed…
  • CVE-2026-102095 CVSS 9.1 critical Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway…
  • CVE-2026-102094 CVSS 7.2 high Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code…
  • CVE-2026-102089 CVSS 7.2 high Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function…