{"ok":true,"trend":{"id":535086,"platform":"mastodon","region":"global","key":"🚨 cve-2026-102149 — cvss 9.4 critical kiteworks email protection gateway did not sufficiently restrict which account a c","title":"🚨 CVE-2026-102149 — CVSS 9.4 CRITICAL Kiteworks Email Protection Gateway did not sufficiently restrict which account a c","url":"https://mastodon.social/@stemshop/117362273548126104","first_seen":"2026-09-30T22:28:07.063619Z","last_seen":"2026-09-30T22:28:07.063619Z","last_rank":7,"peak_rank":6,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.8359375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A critical vulnerability, CVE-2026-102149, with a CVSS score of 9.4 has been disclosed in Kiteworks' Email Protection Gateway. The flaw stems from insufficient restrictions on which account a certificate could be assigned to, potentially letting an attacker associate a certificate with another user's account and compromising confidentiality. Security observers are flagging the issue and urging organizations using the gateway to review exposure and apply fixes.","why":"A newly disclosed critical vulnerability in a widely used secure email gateway raises immediate concerns about certificate-based account impersonation.","tone":"negative","entities":["Kiteworks","CVE-2026-102149","Email Protection Gateway"],"summarized_at":"2026-09-30T22:29:42.541656Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":2049},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical Kiteworks Email Gateway Flaw Tracked as CVE-2026-102149","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-30T22:28:07.063619Z","rank":6,"volume":0},{"captured_at":"2026-09-30T22:28:07.063619Z","rank":7,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@stemshop/117362273548126104","author":"stemshop","title":null,"snippet":"🚨 CVE-2026-102149 — CVSS 9.4 CRITICAL Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and…","posted_at":"2026-09-30T22:09:35.969000Z","likes":0}],"elsewhere":[],"window":"7d"}}