- CVE-2026-101276 CRITICAL CVSS 9.2 -
NVD: iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in...
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 9.2 (CRITICAL); EPSS percentile 32; sources: NVD.
- CVE-2026-102095 CRITICAL CVSS 9.1 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. NVD: Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. NVD: A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal...
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.1 (CRITICAL); EPSS percentile 17; sources: NVD.
- CVE-2026-102102 CRITICAL CVSS 9.1 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). NVD: A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. NVD: The requests are triggered while the gateway retrieves an issuer certificate in an inbound message.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.1 (CRITICAL); EPSS percentile 17; sources: NVD.
- CVE-2026-102103 CRITICAL CVSS 9.1 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). NVD: A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. NVD: The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.1 (CRITICAL); EPSS percentile 13; sources: NVD.
- CVE-2026-102104 CRITICAL CVSS 9.1 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). NVD: A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. NVD: The requests are triggered while the gateway performs an online certificate status check for an inbound message.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 9.1 (CRITICAL); EPSS percentile 13; sources: NVD.
- CVE-2024-58387 HIGH CVSS 8.7 -
NVD: Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. NVD: Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. NVD: Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 8.7 (HIGH); EPSS percentile 44; sources: NVD.
- CVE-2023-54403 HIGH CVSS 8.7 -
NVD: Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath... NVD: Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files containing database or service credentials. NVD: Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary; CVSS 8.7 (HIGH); EPSS percentile 38; sources: NVD.
- CVE-2023-54402 HIGH CVSS 8.7 -
NVD: iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default token value (testtoken) to bypass authentication. NVD: Attackers can exploit the unrestricted URL scheme handling, including file:// URIs, to read arbitrary local files such as operating-system and application configuration files, and to reach internal network hosts and services not otherwise accessible. NVD: Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-26.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review · remote exposure · authenticated boundary; CVSS 8.7 (HIGH); EPSS percentile 37; sources: NVD.
- CVE-2026-102100 HIGH CVSS 8.7 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. NVD: A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. NVD: This could be used to perform actions on the victim's behalf and may have permitted account takeover, including of higher-privileged users.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 8.7 (HIGH); EPSS percentile 11; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102092 HIGH CVSS 8.7 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary JavaScript in another user's authenticated session when they preview shared content. NVD: This could potentially lead to session compromise and account takeover.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 8.7 (HIGH); EPSS percentile 10; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102101 HIGH CVSS 8.1 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. NVD: A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. NVD: Exploitation depends on an attacker first being able to influence the affected data, so this issue is not exploitable on its own.
An attacker may be able to run code or commands on affected systems; CVSS 8.1 (HIGH); EPSS percentile 21; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102091 HIGH CVSS 7.5 -
NVD: Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. NVD: This could potentially be used to reach internal-only services or other network-restricted resources.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 23; sources: NVD.
- CVE-2026-102096 HIGH CVSS 7.2 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. NVD: A crafted package could cause the underlying system to execute arbitrary operating-system commands, potentially with elevated privileges, on the affected appliance.
An attacker may be able to run unintended system commands through the affected component; CVSS 7.2 (HIGH); EPSS percentile 64; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102097 HIGH CVSS 7.2 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. NVD: Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. NVD: A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.
An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 52; sources: NVD.
- CVE-2026-102099 HIGH CVSS 7.2 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. NVD: An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the... NVD: Exploitation requires an existing, authenticated administrative account with access to the affected export function.
An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 49; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102089 HIGH CVSS 7.2 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. NVD: This could potentially be leveraged to execute arbitrary code on the underlying system.
An attacker may be able to run code or commands on affected systems; CVSS 7.2 (HIGH); EPSS percentile 41; sources: NVD.
- CVE-2026-102094 HIGH CVSS 7.2 -
NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. NVD: An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.2 (HIGH); EPSS percentile 39; sources: NVD.
- CVE-2026-102093 HIGH CVSS 7.2 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to...
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.2 (HIGH); EPSS percentile 25; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102098 HIGH CVSS 7.2 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. NVD: A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. NVD: Exploitation requires an existing, authenticated administrative account with access to the affected reporting function.
An attacker may be able to read or change database-backed application data; CVSS 7.2 (HIGH); EPSS percentile 24; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.
- CVE-2026-102090 MEDIUM CVSS 4.3 accellion / kiteworks
NVD: Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. NVD: A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to be loaded and displayed under the trust of the legitimate application domain. NVD: This could increase the credibility of phishing attempts relying on malicious links embedded in the displayed content.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 9; affected product context: accellion / kiteworks; sources: NVD, Vendor Advisory.