CVE-2026-28270: Accellion Kiteworks

High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue.

Affected products

  • Accellion Kiteworks: before 9.2.0 (fixed in 9.2.0)

Published 2026-02-27. Last modified 2026-06-17.