Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #8
Critical stored XSS flaw reported in Kiteworks Core
Original: 🚨 CVE-2026-102147 — CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unau
Security researchers are flagging CVE-2026-102147, a critical vulnerability in Kiteworks Core carrying a CVSS score of 9.3. The flaw is a stored cross-site scripting weakness that could let an unauthenticated attacker plant crafted content which then executes arbitrary JavaScript in the session of an administrator who views it, potentially giving attackers privileged access. Organizations running Kiteworks are urged to review the advisory and apply patches.
Why now: System administrators and security teams are spreading alerts about a newly disclosed critical flaw that could compromise admin sessions in widely used secure file-sharing software.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/535088