CVE-2026-102116: Accellion Kiteworks

High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.

-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.

Affected products

  • Accellion Kiteworks: before 9.5.0 (fixed in 9.5.0)

Published 2026-09-30. Last modified 2026-10-08.