Kiteworks EPG flaw enables unauthenticated root RCE
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Input-handling flaws in Kiteworks Email Protection Gateway allow unauthenticated remote attackers to gain root-level code execution; no known exploitation yet.
CIS/MS-ISAC issued an advisory for a vulnerability (CVE-2026-54154) affecting Kiteworks Email Protection Gateway (EPG), a cloud-based email encryption and policy enforcement appliance. A combination of input-handling flaws in publicly reachable endpoints allows an unauthenticated remote attacker to achieve arbitrary code execution, and by chaining additional local weaknesses, escalate to full root/administrative control of the appliance. This maps to MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) under the Initial Access tactic.
All versions of Kiteworks EPG prior to 9.4.1 are affected. There are currently no reports of in-the-wild exploitation, but the combination of unauthenticated access, public-facing exposure, and root-level compromise potential makes this a high-priority patching item for organizations running the affected appliance. Complete compromise of the device could expose or manipulate sensitive email traffic subject to the gateway's encryption and policy enforcement.
CIS recommends immediate patching to version 9.4.1 or later after testing, alongside standard hardening measures: vulnerability management and remediation processes, automated patch management, network segmentation (isolating the appliance via DMZ), least-privilege configuration, penetration testing, and management of default/service accounts. No IOCs, threat actors, or malware are associated with this advisory as it describes a vulnerability disclosure rather than observed exploitation.
Mentioned in this report
Detection guidance
Web Server Process Spawning Shell With Download or Reverse-Shell Command
Web server or application worker (httpd/apache2/nginx/php-fpm/tomcat) spawning a shell that runs download, reverse-shell or encoded-payload commands - generic post-exploitation pattern for unauthenticated RCE on public-facing appliances such as the Kiteworks EPG flaw. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Web Server Process Spawning Shell With Download or Reverse-Shell Command
description: Detects a web server or application worker process spawning a shell whose
command line fetches a payload, opens a reverse shell or decodes an encoded payload.
Generic post-exploitation behaviour for unauthenticated RCE in public-facing appliances
(e.g. CVE-2026-54154 in Kiteworks EPG); the advisory gives no exploit-specific artefacts,
so this keys on the parent/child relation and command patterns rather than any endpoint
or payload.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-kiteworks-epg-email-security-gateway-could-allow-for-arbitrary-code-execution_2026-107
tags:
- attack.initial-access
- attack.t1190
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- /httpd
- /apache2
- /nginx
- /php-fpm
- /tomcat
- /lighttpd
selection_child:
Image|endswith:
- /sh
- /bash
- /dash
selection_cmd:
CommandLine|contains:
- curl
- wget
- /dev/tcp/
- nc -e
- ncat
- mkfifo
- base64 -d
- bash -i
- chmod +x
condition: selection_parent and selection_child and selection_cmd
falsepositives:
- Web applications or admin panels that legitimately shell out to curl or wget for
health checks or update retrieval
- Legacy CGI scripts that invoke wget or curl through a shell
level: medium
id: 5c4087f4-cbc9-53f9-9c46-abdfc275c25c
status: experimental
author: Vorant
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-kiteworks-epg-email-security-gateway-could-allow-for-arbitrary-code-execution_2026-107
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,582 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs