Cybersecurity

Kiteworks Restores Customer Systems After Fixing Critical Vulnerability

Kiteworks lifted its precautionary warning to shut down systems after fixing a critical vulnerability in a feature used by fewer than 1% of customers, confirming that no breach or exploitation had been detected. The company has not yet disclosed details of the vulnerability or its CVE number.

2026-09-29
3 min read
1 views
certi.news Editorial Team
Kiteworks Restores Customer Systems After Fixing Critical Vulnerability
Kiteworks restored hosted customer systems to service and lifted its recommendation to shut down servers after developing a fix for a critical vulnerability in one of its platform’s features. The company said it found no evidence that any of its systems or customer systems had been breached, and it detected no suspicious activity during the monitoring period.

On Saturday, the company had asked customers worldwide to temporarily shut down Kiteworks servers after receiving a warning from federal intelligence authorities about the possibility of an imminent cyberattack. On September 27, it announced that the shutdown recommendation was no longer in effect and urged customers who had not restarted their systems to return them to service.

What did the company fix?

Kiteworks explained that it fixed a critical vulnerability in an unnamed feature used by fewer than 1% of its total customers. It also added an additional layer of protection to all environments and said that all its other products were unaffected and that it had no indicators that the vulnerability had actually been exploited.

Customers hosting a self-managed version of Kiteworks Advanced Forms need to contact the company’s support team for the necessary assistance. As for hosted systems, the company returned them to operation after completing remediation and monitoring procedures.

Why does this matter?

Kiteworks operates a private content network that brings together enterprise email, file sharing, managed file transfer, APIs, and web forms. The platform serves thousands of companies and government entities, with more than 100 million users of its private data network, making the precautionary shutdown decision operationally significant even though the affected feature is limited to a small percentage of customers.

The incident is additionally significant because file-sharing and file-transfer platforms typically handle sensitive documents and have previously been targeted in data-theft and extortion attacks. The company’s name is also associated with Accellion, the name Kiteworks was formerly known by, and with a campaign in which the Clop gang exploited vulnerabilities in the legacy File Transfer Appliance software, leading to breaches affecting multiple organizations and companies.

What remains unknown?

Kiteworks has not disclosed details of the vulnerability it fixed, and no CVE number has yet been assigned to it to facilitate tracking and verification of its updates. Shadowserver also identified nearly 400 Kiteworks instances accessible online, including 234 in the United States, without specifying how many systems had been updated or represented honeypots.

Editorial reading: The key action here is Kiteworks’ shift from a broad shutdown recommendation to a restart conditional on a centralized fix and continuous monitoring—not an announcement of a confirmed breach. However, the absence of technical details and a CVE number limits security teams’ ability to independently verify the scope of the risk. Therefore, reviewing self-hosted versions and contacting support remain priorities for affected customers.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news