Kiteworks acompany specializing in secure file sharing and the protection of sensitive corporate data, announced that it has fixed a critical vulnerability and lifted the temporary outage recommendation it had issued to its customers. The precautionary directive was issued on Saturday, September 26, 2026, following a warning from federal intelligence agencies of a possible imminent cyberattack.

The company, formerly known as Accellion, initially asked its customers to temporarily shut down their servers to limit the risk of potential security vulnerabilities being exploited. On Monday, September 28, however, it announced that systems could be brought back onlineas ongoing monitoring had revealed no signs of a breach or suspicious activity.
Although the company claims that there is no evidence that the vulnerability was exploited by attackers, the incident highlights the risks faced by corporate data management and transfer platforms.
Kiteworks fixed the vulnerability and restored functionality
According to Kiteworks' announcement, the outage advisory was lifted on September 27, allowing customers who had not already restarted their systems to do so.
See also: CVE-2026-86950: Apple fixes zero-day discovered by Meta
The company clarified that it developed and implemented a corrective solution within the time frame following the initial warning. At the same time, it added an additional layer of protection to its environments, seeking to limit the possibility of exploitation of this particular vulnerability.
The vulnerability was found in a feature used by less than 1% of the company's customers. Kiteworks did not disclose which feature was affected, nor has it yet published a CVE identifier, which would allow system administrators and security researchers to more easily track the issue.
Specific guidance was given to customers using self-hosted Kiteworks Advanced Forms. These organizations were asked to contact technical support for instructions on how to safely address the issue.
The company also emphasized that its other products were not affected by this vulnerability.

Why the warning led to a preventive shutdown of servers
The initial decision to temporarily shut down shows how important rapid response can be when there are indications of a potential attack on corporate infrastructure.
In such cases, disconnecting a system from the internet or temporarily disabling it can reduce the attack surface, particularly when the way in which a vulnerability could be exploited has not yet been fully determined.
This approach may cause temporary disruptions to business operations, but may prove necessary when the security of sensitive information.
In the case of Kiteworks, the warning was based on information from federal agencies, without any details being made public about the possible perpetrator, target, or mechanism of the planned attack.
See also: Citrix NetScaler – CISA: Vulnerability patching by September 30
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The absence of evidence of a breach is a positive development, but it does not amount to absolute proof that no systems were compromised. The assessment depends on the completeness of the log files, the coverage of the monitoring systems, and the results of the technical investigation.
Nearly 400 Kiteworks installations identified online
Threat monitoring organization Shadowserver identified nearly 400 Kiteworks installations that were accessible over the internet. Of these, 234 were located in the United States.
This data shows the platform's presence on publicly accessible infrastructure, without proving that the servers in question were vulnerable or had been compromised. It is also unclear how many of the installations recorded were honeypots, i.e. systems used to observe suspicious activity, or how many had already received the relevant patch.
The distinction is important, as simply exposing a service to the internet does not automatically mean it is vulnerable. However, publicly accessible servers are often the target of automated scans, through which attackers look for outdated software, incorrect configurations, or known security vulnerabilities.
For corporate system administrators, inventorying installations, applying updates, and restricting access to services that don't need to be public are key risk mitigation measures.

The previous Accellion case and the Clop group
Today's warning takes on added significance due to Accellion's history of attacks on corporate file transfer platforms.
In 2020 and 2021, the Clop exploited vulnerabilities in the older Accellion File Transfer Appliance (FTA), which was used to exchange sensitive files between organizations. The attacks were linked to data theft and extortion incidents, affecting businesses and public entities in different countries.
Among the organizations affected were Shell, Qualys, Kroger, Singtel, the Reserve Bank of New Zealand and the Australian Securities and Investments Commission (ASIC), as well as universities and public services.
Accellion had reported at the time that about 300 customers were using FTA, of which fewer than 100 were breached, while fewer than 24 appeared to have suffered significant data theft.
In February 2021, the security services of the Five Eyes issued a joint warning about attacks and extortion attempts, calling on organizations to restrict access to vulnerable servers and apply available updates.
This historical case concerns the older FTA product and does not prove a connection to the current incident.
See also: CVE-2026-100899: SQL injection in DevaslanPHP project-management
What should businesses do?
Organizations using secure file transfer solutions should confirm which products and versions are running in their environment, contact the vendor for required actions, and check if there are any available updates or special instructions for self-hosted installations.
At the same time, it is important to review logs for unusual connections, access attempts, and unexplained data transfers. Businesses that handle sensitive information also need to maintain secure backups and have a response plan in place for situations where immediate system isolation is required.
The Kiteworks case is a reminder that early warning and rapid patching are critical components of corporate cybersecurity. While there have been no reported exploits of this vulnerability, the lack of public technical details makes it essential to monitor official updates and ensure that each installation is properly protected.
source: www.bleepingcomputer.com
