Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-17 | 2026-09-30 |
|---|---|---|
| ≥90 % | 0 | 392 |
| ≥50 % | 0 | 1149 |
| ≥10 % | 0 | 2 |
| <10 % | 300 | 424 |
A first-day response plan for CVE-2026-84411 in MikroTik RouterOS
A first-day response plan for CVE-2026-84411 in MikroTik RouterOS What is known CVE-2026-84411 affects MikroTik RouterOS before 7.24. CISA published advisory ICSA-26-272-06 on September 29, 2026, assigning a CVSS score of 9.8 Critical and c
CVE-2020-11656 | Oracle ZFS Storage Appliance Kit 8.8 Operating System Image use after free (Nessus ID 352245)
A vulnerability, which was classified as very critical, was found in Oracle ZFS Storage Appliance Kit 8.8. Impacted is an unknown function of the component Operating System Image. Executing a manipulation can lead to use after free. This vu
CVE-2020-11656 | Oracle Communications Network Charging/Control up to 12.0.3 Data Access Pack use after free (Nessus ID 352245)
A vulnerability described as very critical has been identified in Oracle Communications Network Charging and Control 6.0.1/12.0.0/12.0.1/12.0.2/12.0.3. Affected by this vulnerability is an unknown functionality of the component Data Access
CVE-2020-11656 | SQLite up to 3.31.1 ALTER TABLE Statement use after free (ssa-389290 / Nessus ID 352245)
A vulnerability was found in SQLite up to 3.31.1 and classified as critical. Affected is an unknown function of the component ALTER TABLE Statement Handler. Such manipulation leads to use after free. This vulnerability is traded as CVE-2020
CVE-2026-100885 | Krayin laravel-crm up to 2.2.4 admin-config-setup API Endpoint CanInstall.php authorization (EUVD-2026-88049)
A vulnerability described as critical has been identified in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API E
CVE-2026-103585 | Wikimedia Foundation MediaWiki 1.43/1.45/1.46 MediaSearch cross site scripting (EUVD-2026-90431)
A vulnerability identified as problematic has been detected in Wikimedia Foundation MediaWiki 1.43/1.45/1.46. The impacted element is an unknown function of the component MediaSearch. The manipulation leads to cross site scripting. This vul
CVE-2026-19553 | Python Software Foundation up to 3.15.x SSLObject ssl.SSLContext.wrap_bio server_hostname input validation (EUVD-2026-90078)
A vulnerability classified as critical has been found in Python Software Foundation Python up to 3.15.x. The impacted element is the function ssl.SSLContext.wrap_bio of the component SSLObject. This manipulation of the argument server_hostn
CVE-2026-19445 | Python up to 3.15.x SSL Context Management Modules/_ssl.c sni_callback context use after free (EUVD-2026-90077)
A vulnerability classified as problematic was found in Python up to 3.15.x. This affects the function sni_callback of the file Modules/_ssl.c of the component SSL Context Management. Such manipulation of the argument context leads to use af
CVE-2022-45223 | Web-Based Student Clearance System 1.0 /Admin/add-student.php txtfullname cross site scripting (EUVD-2022-48123)
A vulnerability has been found in Web-Based Student Clearance System 1.0 and classified as problematic. Impacted is an unknown function of the file /Admin/add-student.php. This manipulation of the argument txtfullname causes cross site scri
CVE-2022-45221 | Web-Based Student Clearance System 1.0 changepassword.php txtnew_password cross site scripting (EUVD-2022-48121)
A vulnerability, which was classified as problematic, was found in Web-Based Student Clearance System 1.0. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtnew_password results i
CVE-2022-45217 | Book Store Management System 1.0.0 Add New System User Level cross site scripting (EUVD-2022-48117)
A vulnerability has been found in Book Store Management System 1.0.0 and classified as problematic. This affects an unknown part of the component Add New System User Module. Performing a manipulation of the argument Level results in cross s
CVE-2026-54872 | OpenSSL up to 4.0.2 Elliptic-Curve Scalar Multiplication timing discrepancy (Nessus ID 352195)
A vulnerability identified as problematic has been detected in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. Impacted is an unknown function of the component Elliptic-Curve Scalar Multiplication. This manipulation causes observable timing d
CVE-2026-35189 | OpenSSL up to 4.0.2 CRL Distribution Points allocation of resources (Nessus ID 352195)
A vulnerability marked as problematic has been reported in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. The impacted element is an unknown function of the component CRL Distribution Points. Performing a manipulation results in allocation o
CVE-2026-84782 | OpenSSL up to 4.0.2 DTLS retransmission logic SSL_read out-of-bounds (Nessus ID 352195)
A vulnerability identified as critical has been detected in OpenSSL up to 3.0.22/3.4.7/3.5.8/3.6.4/4.0.2. This affects the function SSL_read of the component DTLS retransmission logic. Performing a manipulation results in out-of-bounds read
IT Security News Hourly Summary 2026-10-01 01h : 5 posts
5 posts published in the last hour 22:31Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) 22:31Meta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home 2
CVE-2026-96355: How to Inventory Drupal Extensions Before You Patch
CVE-2026-96355: How to Inventory Drupal Extensions Before You Patch Patching is the easy half of the work. Knowing what you actually run is the harder half, and this advisory makes that ordering unavoidable. Vulnerability overview The CERT-
Secure Private Access and managed services: scoping CVE-2026-88771 beyond the appliance
Secure Private Access and managed services: scoping CVE-2026-88771 beyond the appliance Vulnerability overview NCSC-NL advisory NCSC-2026-0394 covers eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The most severe, CVE-
Cisco SD-WAN Manager Zero-Day CVE-2026-76504 Grants Unauthenticated Admin API Access
TL;DR what: Cisco disclosed on September 30 that attackers are exploiting CVE-2026-76504, a URI-encoding flaw in Catalyst SD-WAN Manager that bypasses API authentication. impact: An unauthenticated attacker who can reach the Manager API can
Managed file transfer keeps returning to the news, and the findings look similar each time
Two reports in September 2026 put managed file transfer products back in front of defenders. watchTowr published analysis of a pre-authentication remote code execution chain in Progress ShareFile, tracked as CVE-2026-2699 and CVE-2026-2701.
Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in
CVE-2026-101861 | langflow-ai Langflow up to 1.11.x Component Toolkit schema.py ComponentToolkit.get_tools code injection (WID-SEC-2026-3616)
A vulnerability, which was classified as critical, has been found in langflow-ai Langflow up to 1.11.x. Impacted is the function ComponentToolkit.get_tools of the file schema.py of the component Component Toolkit. This manipulation causes c
CVE-2026-92371 | TeamViewer Full Client/Host up to 15.81 Cloud Session Recording race condition (WID-SEC-2026-3670)
A vulnerability was found in TeamViewer Full Client and Host up to 15.81. It has been rated as very critical. This impacts an unknown function of the component Cloud Session Recording. Performing a manipulation results in race condition. Th
CVE-2026-92370 | TeamViewer up to 15.81 Setting access control (WID-SEC-2026-3670)
A vulnerability, which was classified as problematic, was found in TeamViewer up to 15.81. This issue affects some unknown processing of the component Setting Handler. Executing a manipulation can lead to improper access controls. This vuln
CVE-2023-54403 | Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. Exploitation evidence w
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an u
CVE-2026-102105 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending o
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker
CVE-2026-102106 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authentic
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password chec
CVE-2026-102107 | Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or information from a recipient under a trusted identity; exploitation requires the feature to be enabled for the attacker's profile and the targeted
Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authori
CVE-2024-58387 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration
Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ex
CVE-2026-102108 | An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code executi
CVE-2026-102109 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could po
CVE-2023-54402 | iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and servi
iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication
CVE-2026-102110 | An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not ye
An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-tr
CVE-2026-102111 | Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the control continued to appear enabled in the administrative interface and audit log, allowing it to be silently rendered ineffective.
Kiteworks did not enforce the maximum permitted value for a configurable security-policy setting. An authenticated administrator could set this value outside its intended range so that the associated control never activated, while the contr
CVE-2026-102112 | A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root and run arbitrary commands with the highest pr
CVE-2026-102113 | A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to
A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a
CVE-2026-102114 | A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrati
CVE-2026-102115 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.
Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password
CVE-2026-102116 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the un
CVE-2026-102117 | On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to a destination of their choosing. That destination could then have operating-system commands executed on the node and receive their output, potentially resulting in remote code execution with the privileges of a local serv
On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect the underlying system's outbound support connection to
CVE-2026-102118 | A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.
CVE-2026-102119 | A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.
A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to exe
CVE-2026-102120 | A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another node of the same cluster. Insufficient input validation in an internal cluster management function let attacker-supplied values reach a privileged execution context; exploitation requires existing access to a node in the clu
A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment to run operating system commands with elevated privileges on another no
CVE-2026-102121 | A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web address of a published form could potentially retrieve the form owner's Kiteworks account profile, including personal details, along with parts of the deployment's configuration settings; no passwords, authentication token
A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned more data than the form itself required. Anyone who knew the web
CVE-2026-102104 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs an online certificate status check for an inbound message. Dep
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker
CVE-2026-102122 | Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other members of that folder.
Kiteworks did not correctly enforce which roles a shared folder's manager was permitted to assign. In a default configuration, an authenticated user holding the Manager role on a folder could grant the Owner role to themselves or to other m
CVE-2026-102123 | A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially compromising the integrity of the appliance or rendering it unavailable until an operator intervenes. Exploitation requires network access to the affected interface, which is not reachable on a fully configured appliance in
A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a file to any location writable by the affected service account, potentially c
CVE-2026-102103 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Dependin
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker
CVE-2026-102124 | A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup records, including a contact name and email address captured during initial configuration.
A Kiteworks appliance setup interface did not enforce authentication once the appliance had completed initial configuration. An unauthenticated attacker with network access to the appliance could read and modify a limited set of setup recor
CVE-2026-102125 | The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the service account that runs the application, which could allow an attacker in that position to read or modify application data and configuration, or to disrupt the service on the affected appliance.
The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox could potentially escape its confinement and act with the privileges of the
CVE-2026-102126 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have permitted the lower-privileged administrator to escalate to full administrative control of the tenant, including the creation of a new administr
A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated s
CVE-2026-102127 | An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted
CVE-2026-102128 | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not alread
CVE-2026-102129 | A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges.
A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an
CVE-2026-102130 | Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execut
CVE-2026-102131 | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a
CVE-2026-102133 | An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service account running the connector, enabling code execution in that account's context; exploitation additionally requires network egress from the applianc
An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject addit
CVE-2026-102102 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker
CVE-2026-102134 | Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were not applied.
Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which
CVE-2026-102135 | On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.
On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execut
CVE-2026-102136 | In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficient validation, potentially allowing OS commands to be executed there. Execution was limited to an unprivileged service account on that node.
In multi-node deployments, an attacker who had already obtained code execution on one appliance node could submit a value through an internal cluster interface that was written into monitoring configuration on another node without sufficien