
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks says it discovered and fixed a previously unknown critical vulnerability during a scheduled nine-hour precautionary shutdown. The flaw was confined to a capability enabled for under 1% of customers, and there is no evidence it was ever exploited.
Kiteworks said on Monday, September 28, that it worked with federal intelligence authorities over the weekend and identified a previously unknown critical vulnerability during its scheduled precautionary shutdown, fixing it inside the same window. The company develops a platform for secure file exchange and was previously known as Accellion.
What the shutdown turned up
"During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company said in a statement. "Kiteworks developed and deployed a fix during the window, [and] applied an additional protective layer across all environments."
According to the company, there is no evidence the vulnerability has ever been exploited in a malicious context, and other Kiteworks products are not affected by the flaw.
The nine-hour takedown request
The discovery follows an alert issued days earlier: Kiteworks urged customers to take their systems offline for nine hours and shut down the environments it hosts on their behalf after receiving intelligence about a potentially imminent cyber attack. The company stressed that the measure was more preventative than a reaction to a confirmed breach of its own systems. The shutdown recommendation was lifted on September 27, 2026.
No CVE identifier yet
Kiteworks has not disclosed specifics about the nature of the flaw or how it could be exploited, and as of publication it does not have a Common Vulnerabilities and Exposures (CVE) identifier. The Hacker News contacted the company to ask whether it plans to release a public advisory and assign a CVE ID to make tracking easier.
"Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them," Kiteworks CISO Frank Balonis said. "We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with. That decision is what made the rest possible. We would make the same call again tomorrow to protect our customers' data."
Systems can come back online
Now that the threat window has passed and no anomalies were observed, customers are recommended to bring their Kiteworks system back online.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.