CVE-2025-53899High· 7.2▾ TwilightKiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administr…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is vulnerable to an incorrectly specified destination in a communication channel which allows an attacker with administrative privileges on the system under certain circumstances to intercept upstream communication which could lead to an escalation of privileges. This issue has been patched in version 9.1.0.
kiteworks_managed_file_transfer < 9.1.0Upgrade past the affected range:
kiteworks_managed_file_transfer 9.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-53900Medium· 6.5Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53896High· 7.1Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53897Medium· 6.8Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-53939Medium· 6.3Kiteworks is a private data network (PDN)
CVE-2026-102150High· 7.2A function in the Kiteworks Advanced Forms component was reachable without authentication
CVE-2026-102149Critical· 9.4Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to