# Kiteworks EPG flaw enables unauthenticated root RCE

Published: 2026-10-01 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/c55b98f5-43e3-5280-a2e6-6b3d532fb3d1/kiteworks-epg-flaw-enables-unauthenticated-root-rce

> Input-handling flaws in Kiteworks Email Protection Gateway allow unauthenticated remote attackers to gain root-level code execution; no known exploitation yet.

CIS/MS-ISAC issued an advisory for a vulnerability (CVE-2026-54154) affecting Kiteworks Email Protection Gateway (EPG), a cloud-based email encryption and policy enforcement appliance. A combination of input-handling flaws in publicly reachable endpoints allows an unauthenticated remote attacker to achieve arbitrary code execution, and by chaining additional local weaknesses, escalate to full root/administrative control of the appliance. This maps to MITRE ATT&CK technique T1190 (Exploit Public-Facing Application) under the Initial Access tactic.

All versions of Kiteworks EPG prior to 9.4.1 are affected. There are currently no reports of in-the-wild exploitation, but the combination of unauthenticated access, public-facing exposure, and root-level compromise potential makes this a high-priority patching item for organizations running the affected appliance. Complete compromise of the device could expose or manipulate sensitive email traffic subject to the gateway's encryption and policy enforcement.

CIS recommends immediate patching to version 9.4.1 or later after testing, alongside standard hardening measures: vulnerability management and remediation processes, automated patch management, network segmentation (isolating the appliance via DMZ), least-privilege configuration, penetration testing, and management of default/service accounts. No IOCs, threat actors, or malware are associated with this advisory as it describes a vulnerability disclosure rather than observed exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2026-54154

## Detection guidance (public sample)

### Web Server Process Spawning Shell With Download or Reverse-Shell Command

ATT&CK: T1190

Web server or application worker (httpd/apache2/nginx/php-fpm/tomcat) spawning a shell that runs download, reverse-shell or encoded-payload commands - generic post-exploitation pattern for unauthenticated RCE on public-facing appliances such as the Kiteworks EPG flaw. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Web Server Process Spawning Shell With Download or Reverse-Shell Command
description: Detects a web server or application worker process spawning a shell whose
  command line fetches a payload, opens a reverse shell or decodes an encoded payload.
  Generic post-exploitation behaviour for unauthenticated RCE in public-facing appliances
  (e.g. CVE-2026-54154 in Kiteworks EPG); the advisory gives no exploit-specific artefacts,
  so this keys on the parent/child relation and command patterns rather than any endpoint
  or payload.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-kiteworks-epg-email-security-gateway-could-allow-for-arbitrary-code-execution_2026-107
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /httpd
    - /apache2
    - /nginx
    - /php-fpm
    - /tomcat
    - /lighttpd
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
  selection_cmd:
    CommandLine|contains:
    - curl
    - wget
    - /dev/tcp/
    - nc -e
    - ncat
    - mkfifo
    - base64 -d
    - bash -i
    - chmod +x
  condition: selection_parent and selection_child and selection_cmd
falsepositives:
- Web applications or admin panels that legitimately shell out to curl or wget for
  health checks or update retrieval
- Legacy CGI scripts that invoke wget or curl through a shell
level: medium
id: 5c4087f4-cbc9-53f9-9c46-abdfc275c25c
status: experimental
author: Vorant
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-kiteworks-epg-email-security-gateway-could-allow-for-arbitrary-code-execution_2026-107

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c55b98f5-43e3-5280-a2e6-6b3d532fb3d1/kiteworks-epg-flaw-enables-unauthenticated-root-rce.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
