Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat
Kiteworks briefly told customers to shut down servers over an unconfirmed threat, then lifted the advice.
On September 25, 2026, Kiteworks told self-managed and hosted customers to take systems offline after U.S. federal authorities shared intelligence that a threat actor might target its secure file-transfer platform. The vendor called the move preventive, said it had no evidence of compromise, did not assign a CVE, and urged customers to run version 9.5.1. Described shutdown windows ranged from about six to nine hours. On September 27 Kiteworks lifted the recommendation, said hosted environments were restored, and noted listed subsidiaries were outside the advisory.
- Federal intelligence suggested a threat actor might target some Kiteworks systems.
- Kiteworks reported no confirmed compromise, exploit, or CVE.
- Customers were urged to remain on version 9.5.1.
- The shutdown recommendation was lifted on September 27 after restoration.
Full article483 words · extracted from gbhackers.com · click to collapse
Kiteworks has lifted its emergency shutdown recommendation after advising customers to temporarily take their systems offline in response to credible intelligence indicating that a threat actor may target its platforms.
The company clarified that this action was preventive and did not indicate a confirmed compromise. It also urged customers to remain on the latest version 9.5.1.
Based in San Mateo, California, Kiteworks issued this unusual advisory on September 25 after receiving threat intelligence from federal authorities.
Initially, the company requested organizations operating self-managed Kiteworks environments, whether on-premises, on AWS, or Microsoft Azure, to observe a coordinated precautionary shutdown window based on their local time zones. Kiteworks stated that it would shut down and later restore the environments it hosts for customers.
The warning drew attention because it seemed related to a potential zero-day attack, which involves exploitation paths not necessarily covered by known vulnerabilities or available patches.
Reports based on customer communications indicated that the vendor was worried about vulnerabilities unknown to Kiteworks, making it impossible to rule out potential unauthorized access routes, even for systems not directly exposed to the public internet.
Kiteworks’ Chief Information Security Officer, Frank Balonis, noted that federal intelligence authorities provided credible information suggesting that a threat actor “may attempt to target some Kiteworks systems.”
He emphasized that there were no indications that Kiteworks’ infrastructure or customer systems had been compromised, describing the shutdown as a measure to reduce risk while the company worked with authorities.
“The advisory is preventative rather than a response to a confirmed breach,” the company stated. Kiteworks also said it had addressed all known vulnerabilities in version 9.5.1 and encouraged customers to run that release. However, the company did not confirm the existence, exploitation, technical cause, or CVE assignment of a specific zero-day vulnerability.
Initial reports indicated a six-hour shutdown period for some customer regions, while Kiteworks’ later formal advisory referred to a nine-hour local-time window.
This discrepancy likely reflects different customer communications or an expanded operational response. Nevertheless, the recommendation represented an exceptional step for an enterprise secure-file-transfer and data-exchange provider, whose products are widely used to transmit regulated and sensitive information.
On September 27, Kiteworks announced that it had lifted the shutdown recommendation for all customers. It stated that organizations that had not yet restarted could bring their Kiteworks systems back online.
At the same time, all Kiteworks-hosted customer environments had already been restored and were operating normally. The company advised customers using self-hosted Advanced Forms to contact technical support for environment-specific assistance.
Kiteworks specified that the advisory did not affect its subsidiaries and associated businesses, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.