Vulnerabilities
CVE-2026-28271 - Kiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)
CVE ID : CVE-2026-28271 Published : Feb. 27, 2026, 9:16 p.m. | 19 minutes ago Description : Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version 9.2.0 contains a patch for the issue. Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Attack Vector:
network
Impact:
SSRF