CVE-2025-53897: Accellion Kiteworks Managed File Transfer

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an external attacker to gain access to log information from the system by tricking an administrator into browsing a specifically crafted fake page of Kiteworks MFT. This issue has been patched in version 9.1.0.

Affected products

  • Accellion Kiteworks Managed File Transfer: before 9.1.0 (fixed in 9.1.0)

Published 2025-11-29. Last modified 2026-10-07.