Kiteworks has released a major security update that addresses 126 vulnerabilities across its secure data transfer platform and associated applications.

The update includes fixes for critical account takeover flaws, high-severity code execution bugs, security bypass issues, unauthorized data modification, privilege escalation, and denial-of-service conditions.

The company published the vulnerabilities through its public security advisories repository, which provides affected-version details and remediation guidance for Kiteworks products.

Organizations using Kiteworks Core, Kiteworks Secure Data Forms, and Kiteworks Email Protection Gateway should review their deployed versions and apply the latest updates as soon as possible.

The most severe findings affect Kiteworks Core and Kiteworks Email Protection Gateway versions before 9.5.1. Both products were affected by critical account takeover vulnerabilities tracked as GHSA-xgh2-fgj6-w93r and GHSA-c9w5-4frw-7wqq.

Successful exploitation could allow an attacker to take control of a user account, potentially gaining access to sensitive files, email workflows, data-sharing functions, or administrative capabilities depending on the compromised account’s privileges.

Kiteworks Patches 126 Vulnerabilities

Kiteworks Core versions before 9.5.1 were also vulnerable to arbitrary code execution, tracked as GHSA-gmgg-7xhc-75f9. Code execution flaws are especially dangerous because they can let an attacker run malicious commands on a targeted server. In enterprise environments, this could enable data theft, persistent access, lateral movement, or ransomware deployment.

Another high-severity Core issue, GHSA-m39v-w8fv-gf3m, could allow privilege escalation. An attacker with limited access may be able to obtain permissions beyond those intended by administrators.

Kiteworks Core also received a fix for a moderate-severity flaw, GHSA-h97r-j99c-q8xc, which could expose internal network resources to an unauthorized party.

The update also resolves several issues in Kiteworks Email Protection Gateway before version 9.5.1. The affected vulnerabilities include unauthorized file modification flaws tracked as GHSA-5pgq-v8g2-rg2f and GHSA-3p9g-jh62-8f89, along with a moderate denial-of-service issue identified as GHSA-wwhf-5862-rjxq.

Unauthorized file modification weaknesses could allow malicious changes to files the gateway processes or protects. At the same time, denial-of-service attacks could interrupt email security operations.

Kiteworks Secure Data Forms versions before 9.5.0 were affected by a high-severity unauthorized data modification vulnerability (GHSA-9×72-vqwh-v4hv). The company also fixed a separate high-severity security bypass issue in Secure Data Forms versions before 9.5.1, tracked as GHSA-vwvw-rp3m-rm37.

Kiteworks said it discloses vulnerability details for up to 12 months after releasing a fix. Existing customers can obtain product-specific remediation information through release notes distributed with each update.

Security teams should upgrade affected deployments to version 9.5.1 or later, where applicable, verify exposed Kiteworks services, review account activity for suspicious access and ensure administrative accounts use strong authentication controls.

Organizations should also assess whether internet-facing Core, Email Protection Gateway, or Secure Data Forms instances were reachable before patching.