# Kiteworks patches over 60 security flaws

Published: 2026-10-08 · Severity: routine
Canonical: https://vorant.io/reports/ee141405-04d1-5186-b71a-680d846963a6/kiteworks-patches-over-60-security-flaws

> NCSC-NL advisory details over 60 Kiteworks vulnerabilities, some unauthenticated, that can be chained to achieve admin-level code execution; patches available.

NCSC-NL (Netherlands Cyber Security Center) published an advisory covering a large batch of vulnerabilities fixed in the Kiteworks product line, a secure file-sharing and content-governance platform used by enterprises. The flaws span a wide range of weakness classes including path traversal, arbitrary file write, OS/SQL/XML/code/CRLF injection, cross-site scripting, deserialization of untrusted data, SSRF, authentication bypass, weak password-reset logic, privilege escalation, unrestricted file upload, unsafe reflection, XXE, and open redirect. Several of the most severe issues carry CVSS scores of 9.1-9.8 and affect administrative import/export functions, cluster/appliance node communication, and certificate handling.

Most of the vulnerabilities require authenticated administrative access to exploit, but NCSC-NL notes that some can be abused without prior authentication — notably during initial setup or via unprotected interfaces — and that these unauthenticated issues can potentially be chained with the privilege-escalation bugs to achieve full administrative control. Exploitation outcomes described include arbitrary file writes leading to code execution, session hijacking via XSS, unauthorized database access via SQL injection, access to internal network resources via SSRF, interception of encrypted communications through certificate-handling flaws, and denial of service through resource exhaustion.

Kiteworks has released updates addressing all listed CVEs (70 identifiers referenced, CVSS 3.3–9.8). There is no indication in the advisory of active in-the-wild exploitation; this is a vendor-patch disclosure. Defenders running Kiteworks should prioritize patching to the fixed versions referenced in the vendor's own advisories, review administrative account access and initial-setup/interface exposure, and audit cluster/appliance node trust relationships and certificate assignments given the chaining risk toward administrator-level compromise.

## Mentioned in this report

- Vulnerabilities: CVE-2026-102089, CVE-2026-102091, CVE-2026-102092, CVE-2026-102093, CVE-2026-102094, CVE-2026-102095, CVE-2026-102096, CVE-2026-102097, CVE-2026-102098, CVE-2026-102099, CVE-2026-102100, CVE-2026-102101, CVE-2026-102102, CVE-2026-102103, CVE-2026-102104, CVE-2026-102105, CVE-2026-102106, CVE-2026-102108, CVE-2026-102112, CVE-2026-102113, CVE-2026-102114, CVE-2026-102115, CVE-2026-102116, CVE-2026-102117, CVE-2026-102118, CVE-2026-102119, CVE-2026-102120, CVE-2026-102121, CVE-2026-102123, CVE-2026-102125, CVE-2026-102126, CVE-2026-102128, CVE-2026-102129, CVE-2026-102130, CVE-2026-102131, CVE-2026-102132, CVE-2026-102142, CVE-2026-102143, CVE-2026-102147, CVE-2026-102149

## Detection guidance (public sample)

### Linux Web Server Process Spawning Shell With Download or Recon Commands

ATT&CK: T1190

Web server or PHP worker processes spawning a shell that runs download, recon or reverse-shell commands, a generic post-exploitation pattern for injection or file-write-to-code-execution flaws in public-facing apps such as file-sharing appliances. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Linux Web Server Process Spawning Shell With Download or Recon Commands
description: Detects web server or PHP worker processes (apache, httpd, nginx, php-fpm)
  spawning a shell whose command line downloads content, runs recon commands or opens
  a reverse shell. Generic post-exploitation behaviour for OS command injection, deserialization
  or arbitrary file write leading to code execution on public-facing web applications.
  The advisory describes these weakness classes but no product-specific process names,
  so this rule relies on generic web-stack process relations.
tags:
- attack.initial-access
- attack.t1190
- attack.execution
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /apache2
    - /httpd
    - /nginx
    - /php-fpm
    - /php-fpm7
    - /php-fpm8
    - /php
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
  selection_cmd:
    CommandLine|contains:
    - curl
    - wget
    - /dev/tcp/
    - nc -e
    - ncat
    - base64 -d
    - whoami
    - uname -a
    - /etc/passwd
  filter_healthcheck:
    CommandLine|contains:
    - logrotate
    - apachectl configtest
  condition: selection_parent and selection_child and selection_cmd and not filter_healthcheck
falsepositives:
- Web applications that legitimately shell out to curl or wget for update checks or
  integrations
- Administrative troubleshooting scripts invoked via web-based management interfaces
level: medium
id: 12bbc287-02d7-5308-9b14-c5fbf7fce901
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0408.html
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0408.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ee141405-04d1-5186-b71a-680d846963a6/kiteworks-patches-over-60-security-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
