Most vendors do not ask customers to switch production off for a weekend. Kiteworks did. After what it called credible threat intelligence from federal intelligence authorities, the secure file-sharing company (formerly Accellion) recommended a precautionary nine-hour shutdown of on-premises and customer-hosted systems, then lifted that advice on Sunday, September 27.
Systems are back up. The question for Tuesday is simple: are you on the current release, and do you run the one product the company says is affected?
When a file-transfer vendor asks everyone to unplug, the right follow-up is not relief. It is an inventory.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
Kiteworks emailed customers late last week recommending a shutdown window over the weekend, first reported by German outlet Heise. Customers running Kiteworks on-premises or in their own AWS or Azure accounts were asked to power down during that window; Kiteworks shut down the systems it hosts on customers’ behalf itself. A Kiteworks support official told Heise the advisory was tied to a potential zero-day.
On Sunday the company lifted the recommendation. In emails to customers, it said a severe vulnerability in its Advanced Forms secure data collection product triggered the shutdown. Advanced Forms is enabled for fewer than 1% of customers, under 50 organizations, and Kiteworks says the other products (file collaboration, file transfer, email encryption, APIs, and MFT) are unaffected. Customers with self-hosted Advanced Forms were told to contact Kiteworks support.
Kiteworks CISO Frank Balonis said the company has no indication that Kiteworks or customer systems were compromised, that the advisory was preventative, and that all known vulnerabilities are addressed in the current release, 9.5.1. The company is working with partners including Mandiant. No CVE or technical details have been published.
Why it matters
Secure file transfer and file-sharing platforms have been extortion targets for years because they hold exactly what a data-theft crew wants in one place. Kiteworks knows this history better than most: in December 2020, Clop used a zero-day in Accellion’s file transfer appliance to steal data from dozens of organizations. watchTowr’s Jake Knott told The Record that nobody asks an entire customer base to unplug production systems over a weekend on a hunch.
The good news is scope. If you do not use Advanced Forms, the company says you are not affected by this flaw. If you do, the product is small enough that your support conversation should be quick.
What to do first
- Confirm every Kiteworks instance you run, including cloud-hosted ones in your own AWS or Azure accounts, is on 9.5.1.
- Check whether Advanced Forms is enabled. If it is and you self-host it, open a ticket with Kiteworks support today and ask for their specific remediation steps.
- If a system was not shut down during the window, or came back early, pull its access and admin logs for the weekend and keep them.
- Review which external users and forms can reach the instance, and remove anything stale.
- Keep an eye on Kiteworks advisories this week in case a CVE or indicators are published.
Forward this
If we use Kiteworks for secure file sharing: please confirm we are on version 9.5.1 and tell me whether we use the Advanced Forms feature. Kiteworks asked customers to shut down over the weekend after a federal warning and says the flaw is limited to Advanced Forms.
Details
- Vendor: Kiteworks (formerly Accellion)
- Affected product: Advanced Forms secure data collection, per Kiteworks customer email; enabled for fewer than 50 organizations
- Not affected (per Kiteworks): DPE, file collaboration, file transfer, email encryption, APIs, MFT; also subsidiaries including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder
- Current release: 9.5.1 (“all known vulnerabilities” addressed, per Kiteworks)
- Shutdown advisory: precautionary weekend window; lifted September 27, 2026
- Exploitation: none confirmed; CVE not published at time of writing
Hunt / verify
- Check the version in the Kiteworks admin console on every node.
- Confirm whether Advanced Forms is licensed or enabled in your tenant.
- Review weekend authentication and admin activity, new user or form creation, and unusual outbound transfers.
Slack paste: Kiteworks: confirm 9.5.1 everywhere; check if Advanced Forms is enabled (if self-hosted, open a support ticket today); keep weekend logs for any node that stayed online.
Sources
- SecurityWeek: Kiteworks urges server shutdown, finds Advanced Forms vulnerability (Sep 28, 2026)
- The Record: Kiteworks urges customers to stop using platform after warning from federal intelligence agencies (Sep 25, 2026)
- The Cyber Express: Kiteworks shutdown advisory lifted after threat alert (Sep 28, 2026)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.