MikeTrendsTrends right now

search

Kiteworks Core

Trends

  1. 1
    Kiteworks Core deserialization flaw logged as high-severity vulnerabilityโ–ผ๐Ÿšจ EUVD-2026-90276 ๐Ÿ“Š Score: 8.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: core ๐Ÿข Vendor: Kiteworks ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ Kiteworks CoreMmastodonTechnologyCybersecurity016 h ago

    Kiteworks Core versions before 9.5.0 are affected by a deserialization of untrusted data vulnerability, tracked as EUVD-2026-90276 with a CVSS v3.1 score of 8.1. Under certain conditions, the flaw could allow attackers to send crafted data that is deserialized unsafely, potentially leading to code execution. The advisory was updated on September 30, 2026, and users are advised to upgrade to version 9.5.0 or later.

  2. 2
    Critical stored XSS flaw reported in Kiteworks Coreโ—๐Ÿšจ CVE-2026-102147 โ€” CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauMmastodonTechnologyCybersecurity014 h ago

    Security researchers are flagging CVE-2026-102147, a critical vulnerability in Kiteworks Core carrying a CVSS score of 9.3. The flaw is a stored cross-site scripting weakness that could let an unauthenticated attacker plant crafted content which then executes arbitrary JavaScript in the session of an administrator who views it, potentially giving attackers privileged access. Organizations running Kiteworks are urged to review the advisory and apply patches.

  3. 3
    Critical Kiteworks password reset flaw flagged as CVE-2026-102115โ—๐Ÿšจ CVE-2026-102115 โ€” CVSS 9.8 CRITICAL Kiteworks Core did not correctly validate a parameter submitted to the password reMmastodonTechnologyCybersecurity014 h ago

    A critical vulnerability, CVE-2026-102115 with a CVSS score of 9.8, has been disclosed in Kiteworks Core. The flaw stems from improper validation of a parameter in the password reset workflow, potentially letting an unauthenticated attacker who knows a user's email address reset that account's password. Security commentators are sharing the advisory and urging organisations using Kiteworks to patch promptly.