CVE-2026-102127

An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.

  • Published Sep 30, 2026
  • CVSS 7.0 high
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-102127 at the National Vulnerability Database