VYPR

Kiteworks Email Protection Gateway

by Kiteworks

CVEs (2)

  • CVE-2026-29092Mar 25, 2026
    risk 0.00cvss epss 0.00

    Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow unauthorized access to continue until the session naturally expires. Upgrade Kiteworks to version 9.2.1 or later to receive a patch.

  • CVE-2026-28272Feb 27, 2026
    risk 0.00cvss epss 0.00

    Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface. Version 9.2.0 contains a patch for the issue.