CVE-2026-102135: Accellion Kiteworks

Medium severity, CVSS 6.6. EPSS: 1.3% chance of exploitation in the next 30 days.

On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.

Affected products

  • Accellion Kiteworks: before 9.5.1 (fixed in 9.5.1)

Published 2026-09-30. Last modified 2026-10-08.