Kiteworks patches over 60 security flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
NCSC-NL advisory details over 60 Kiteworks vulnerabilities, some unauthenticated, that can be chained to achieve admin-level code execution; patches available.
NCSC-NL (Netherlands Cyber Security Center) published an advisory covering a large batch of vulnerabilities fixed in the Kiteworks product line, a secure file-sharing and content-governance platform used by enterprises. The flaws span a wide range of weakness classes including path traversal, arbitrary file write, OS/SQL/XML/code/CRLF injection, cross-site scripting, deserialization of untrusted data, SSRF, authentication bypass, weak password-reset logic, privilege escalation, unrestricted file upload, unsafe reflection, XXE, and open redirect. Several of the most severe issues carry CVSS scores of 9.1-9.8 and affect administrative import/export functions, cluster/appliance node communication, and certificate handling.
Most of the vulnerabilities require authenticated administrative access to exploit, but NCSC-NL notes that some can be abused without prior authentication — notably during initial setup or via unprotected interfaces — and that these unauthenticated issues can potentially be chained with the privilege-escalation bugs to achieve full administrative control. Exploitation outcomes described include arbitrary file writes leading to code execution, session hijacking via XSS, unauthorized database access via SQL injection, access to internal network resources via SSRF, interception of encrypted communications through certificate-handling flaws, and denial of service through resource exhaustion.
Kiteworks has released updates addressing all listed CVEs (70 identifiers referenced, CVSS 3.3–9.8). There is no indication in the advisory of active in-the-wild exploitation; this is a vendor-patch disclosure. Defenders running Kiteworks should prioritize patching to the fixed versions referenced in the vendor's own advisories, review administrative account access and initial-setup/interface exposure, and audit cluster/appliance node trust relationships and certificate assignments given the chaining risk toward administrator-level compromise.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0408.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,042 reports from 148 sources, 468 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs