Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks patched a critical, previously unknown vulnerability affecting under 1% of customers during a nine-hour precautionary shutdown triggered by attack intelligence.
Kiteworks (formerly Accellion) said it worked with federal intelligence authorities and found a critical flaw in a capability enabled for less than 1% of its customer base during a scheduled precautionary shutdown. A fix was deployed during the window and an additional protective layer was applied across all environments. The company states there is no evidence the flaw was ever exploited, no CVE ID has been assigned, and customers can bring systems back online as of September 27, 2026.
- Critical flaw affects capability enabled for less than 1% of customers
- No evidence of malicious exploitation, no CVE assigned yet
- Fix deployed plus extra protective layer across all environments
- Nine-hour precautionary shutdown lifted September 27, 2026
Full article363 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 29, 2026Vulnerability / Enterprise Security
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown.
"During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company said in a statement. "Kiteworks developed and deployed a fix during the window, [and] applied an additional protective layer across all environments."
There is no evidence that the vulnerability has ever been exploited in a malicious context. Other Kiteworks products are not affected by the flaw.
The development comes days after Kiteworks, previously Accellion, urged customers to take their systems offline for a period of nine hours, in addition to shutting down environments it hosts on behalf of customers, after receiving intelligence about a potential imminent cyber attack.
The company stressed that the action was more preventative than a reaction to a confirmed breach of its systems. On September 27, 2026, the shutdown recommendation was lifted.
Kiteworks has not disclosed any specifics about the nature of the flaw, and how it could be exploited. It does not have a Common Vulnerabilities and Exposures (CVE) identifier as of writing. The Hacker News has contacted the company if it plans to release a public advisory about the flaw and assign it a CVE ID for easier tracking.
"Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them," Kiteworks CISO Frank Balonis said.
"We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with. That decision is what made the rest possible. We would make the same call again tomorrow to protect our customers' data."
Now that the threat window has passed and no anomalies were observed, customers are recommended to bring their Kiteworks system back online.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.