Skip to content
Security & Trust

Kiteworks Advised a Nine-Hour Shutdown Over a Flaw It Says Is in One Product

Kiteworks says the flaw is confined to a product enabled for under 50 organizations.

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Kiteworks Advised a Nine-Hour Shutdown Over a Flaw It Says Is in One Product

AI-generated image for WebPulse. About our images

Key finding

Recommended shutdown window: 9 hours (Source: SecurityWeek, citing Kiteworks customer communication (September 28, 2026))

A precautionary shutdown, lifted by Sunday

SecurityWeek reported on September 28, 2026 that Kiteworks, the secure data-sharing vendor formerly known as Accellion, told customers to take on-premises and customer-hosted instances offline for a "nine-hour precautionary shutdown." SecurityWeek's summary of the Friday communication says hackers may target zero-day vulnerabilities in the company's products. Kiteworks said it had received "credible threat intelligence from federal intelligence authorities" indicating that a threat actor "may attempt to target some Kiteworks systems."

The guidance was withdrawn on Sunday, and customers across the board were free to restart. Environments that Kiteworks runs for customers had resumed normal operation, while those with self-hosted Advanced Forms were directed to Customer Support. The announcement did not detail the threat, and the SecurityWeek report contains no independent assessment of the federal intelligence.

9 hours
Recommended shutdown window
Source: SecurityWeek, citing Kiteworks customer communication (September 28, 2026)

What Kiteworks says about scope

According to SecurityWeek, emails to customers said a severe vulnerability in Advanced Forms, the company's secure data collection product, triggered the shutdown. A copy of one email was shared on Reddit. In it, Kiteworks says the product is enabled for fewer than 1% of its customers, under 50 organizations. It also says the vulnerability is confined to that product, and it names its file transfer, email encryption, APIs and MFT offerings among those it considers unaffected.

These are the vendor's own statements, relayed second-hand. The report cites no outside confirmation of the scope, no CVE identifier, and no word on whether a fix exists for self-hosted Advanced Forms. SecurityWeek's summary of the Friday advisory refers to zero-days in the company's products, while the emails it cites describe a vulnerability confined to Advanced Forms. The report does not reconcile the two.

Fewer than 1% of customers (under 50 organizations)
Advanced Forms enabled, per Kiteworks
Source: Kiteworks customer email, as reported by SecurityWeek (September 28, 2026)

Who carried the decision

The Friday recommendation was framed by deployment type, on-premises and customer-hosted, and each of those customers had to decide whether to act on it. That meant weighing an outage of data-exchange infrastructure against intelligence that the vendor attributes to federal authorities and whose details the announcement did not give. SecurityWeek does not quantify what the outage cost customers.

Kiteworks says it has no evidence the defect was exploited and no indication that its systems or its customers' systems were compromised. It called the advisory "preventative rather than a response to a confirmed breach." The company said it is working with industry partners, Mandiant among them, to share intelligence about the threat. It also said it has accounted for all known vulnerabilities in release 9.5.1 and continues to recommend that customers run the latest version.

Questions to put to your team

1. Can we say within minutes which optional products and features are enabled on each self-hosted file-transfer or data-sharing system we run? Per Kiteworks, the vulnerability is confined to Advanced Forms, which is enabled for under 50 organizations.

2. Who is authorised to take a business-critical transfer system offline on a vendor's advisory alone, and what is the documented process for the first hour?

3. What would a nine-hour window mean for the partners and workflows that depend on these systems? Do we have a fallback route for time-sensitive exchanges?

4. If we run self-hosted Kiteworks, are we on release 9.5.1 or later, and has someone contacted Customer Support if Advanced Forms is enabled?

5. When a vendor cites government intelligence without detail, whom do we call for more, and how soon do we expect an answer?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: SecurityWeek.

Share this insight