Mmastodon TechnologyCybersecurity first seen 1 d ago, last 1 d ago, peak #9
Critical Kiteworks password reset flaw flagged as CVE-2026-102115
Original: 🚨 CVE-2026-102115 — CVSS 9.8 CRITICAL Kiteworks Core did not correctly validate a parameter submitted to the password re
A critical vulnerability, CVE-2026-102115 with a CVSS score of 9.8, has been disclosed in Kiteworks Core. The flaw stems from improper validation of a parameter in the password reset workflow, potentially letting an unauthenticated attacker who knows a user's email address reset that account's password. Security commentators are sharing the advisory and urging organisations using Kiteworks to patch promptly.
Why now: A newly disclosed CVSS 9.8 critical vulnerability in a widely used secure file-sharing product raises urgent patching concerns.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/535089