CVE-2025-53896High· 7.1▾ TwilightKiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could cause under certain circumstances that a user's active session would not properly time out due to inactivity. This issue has been patched in version 9.1.0.
kiteworks_managed_file_transfer < 9.1.0Upgrade past the affected range:
kiteworks_managed_file_transfer 9.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-53899High· 7.2Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53900Medium· 6.5Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53897Medium· 6.8Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53939Medium· 6.3Kiteworks is a private data network (PDN)
CVE-2026-102150High· 7.2A function in the Kiteworks Advanced Forms component was reachable without authentication
CVE-2026-102149Critical· 9.4Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to