{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/email-protection-gateway-epg/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Email Protection Gateway (EPG)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kiteworks"],"content_html":"\u003cp\u003eA vulnerability has been identified in the Kiteworks Email Protection Gateway (EPG) that allows an unauthenticated remote attacker to achieve arbitrary code execution. The EPG platform, used for email encryption, decryption, and policy enforcement, contains input-handling flaws within its publicly accessible web endpoints. By exploiting these flaws, an attacker can execute arbitrary commands with root privileges on the underlying appliance. This represents a significant security risk for organizations using Kiteworks as a perimeter email security solution, as the appliance typically handles sensitive inbound and outbound communications. Successful exploitation leads to a complete system compromise, enabling attackers to intercept, read, or modify enterprise emails or pivot further into the internal network.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full administrative control over the targeted Email Protection Gateway. As the appliance is positioned at the network edge to manage encrypted email traffic, unauthorized root access allows for the total compromise of email data, potential credential theft, and sustained persistence within the organization's communication infrastructure. The number of potentially affected victims includes any enterprise relying on Kiteworks EPG for email security.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of all public-facing Kiteworks EPG instances for anomalous requests originating from untrusted external IPs. Since no specific patch version or CVE identifier was provided in the initial security advisory, contact Kiteworks support immediately to confirm if your specific deployment version is affected and request the relevant security update or mitigation configuration.\u003c/p\u003e\n","date_modified":"2026-10-02T08:12:17Z","date_published":"2026-10-02T08:12:17Z","id":"https://feed.craftedsignal.io/briefs/2026-10-kiteworks-epg-rce/","summary":"An unauthenticated remote code execution vulnerability in Kiteworks Email Protection Gateway (EPG) allows attackers to gain root-level access via input-handling flaws in public endpoints.","title":"Arbitrary Code Execution Vulnerability in Kiteworks Email Protection Gateway","url":"https://feed.craftedsignal.io/briefs/2026-10-kiteworks-epg-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Email Protection Gateway (EPG)","version":"https://jsonfeed.org/version/1.1"}