Kiteworks has 61 CVEs on record. Disclosure cadence is accelerating: 61 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 61. The median CVSS is 7.2 (high), with 9 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-306 (7) and CWE-918 (7). Most affected products: Core (35), Email Protection Gateway (22), Secure Data Forms (4).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 61 prev 0
Products
- Core 35
- Email Protection Gateway 22
- Secure Data Forms 4
61
Total CVEs
9
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-102115Critical· 9.8Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow54CVE-2026-102149Critical· 9.4Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to52CVE-2026-102147Critical· 9.3A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affec…51CVE-2026-102106Critical· 9.1Improper authentication in a Kiteworks Email Protection Gateway administrative service50CVE-2026-102105Critical· 9.1Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF)50
Kiteworks vulnerabilities
CVEs affecting Kiteworks, newest first. Open any entry for full detail, references, and exploit status.
61 CVEsRSS