CVE-2026-28270: Accellion Kiteworks
High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows uploading of arbitrary files without proper validation. Malicious administrators could exploit this to upload unauthorized file types to the system. Version 9.2.0 contains a patch for the issue.
Affected products
- Accellion Kiteworks: before 9.2.0 (fixed in 9.2.0)
Published 2026-02-27. Last modified 2026-06-17.