CVE-2026-24751: Accellion Kiteworks

High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitrary JavaScript code. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.

Affected products

  • Accellion Kiteworks: before 9.3.0 (fixed in 9.3.0)

Published 2026-06-01. Last modified 2026-07-22.