Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
Kiteworks briefly urged server shutdowns after finding a severe, apparently unexploited Advanced Forms vulnerability.
Kiteworks, formerly Accellion, told customers on Friday to shut down on-premises and customer-hosted servers for about nine hours after federal threat intelligence suggested attackers might target its products. The company later said a severe vulnerability in Advanced Forms, enabled for fewer than 1% of customers and under 50 organizations, drove the warning, while other products were unaffected. It reported no evidence of exploitation or compromise and said it was sharing intelligence with partners including Mandiant. On Sunday it lifted the shutdown recommendation; self-hosted Advanced Forms customers were told to contact support, and Kiteworks-hosted systems were restored.
- Federal threat intelligence prompted a nine-hour precautionary customer shutdown.
- A severe flaw is limited to Advanced Forms, used by fewer than 50 organizations.
- Kiteworks reported no evidence of exploitation or customer compromise.
- The shutdown recommendation was lifted Sunday; hosted systems are back online.
- Kiteworks says release 9.5.1 covers all known vulnerabilities.
Full article369 words · extracted from securityweek.com · click to collapse
Secure data sharing solutions provider Kiteworks (formerly Accellion) over the weekend instructed customers to shut down their servers in response to credible threat intelligence from federal authorities.
In a communication to customers on Friday, the company advised a “nine-hour precautionary shutdown” of on-premises and customer-hosted instances, noting that hackers may target zero-day vulnerabilities in its products.
On Sunday, the company announced it had lifted the shutdown recommendation for all customers, and that they could bring their systems back online.
“Customers with self-hosted Advanced Forms should contact Customer Support for assistance. All systems Kiteworks hosts on customers’ behalf have been brought back up and are operating normally,” the company said.
While Kiteworks’s announcement did not detail the threat, the company said in emails to its customers that a severe vulnerability in its Advanced Forms secure data collection product triggered the shutdown.
“Advanced Forms is enabled for fewer than 1% of our customers, under 50 organizations, and the vulnerability is confined to that product only. All other products, including the DPE, file collaboration, file transfer, email encryption, APIs, and MFT, are unaffected,” a copy of the email shared on Reddit reads.
Advertisement. Scroll to continue reading.
The company said it had no evidence the security defect was exploited and that it was working with “industry partners, including Mandiant, to share intelligence about the threat”.
Kiteworks CISO Frank Balonis said:
“Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems. Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities.
We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach. Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version.”
Related: Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug
Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
Related: OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration