CVE-2026-102144: Accellion Kiteworks
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.
Affected products
- Accellion Kiteworks: before 9.5.1 (fixed in 9.5.1)
Published 2026-09-30. Last modified 2026-10-07.