Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Kiteworks, formerly known as Accellion, has confirmed it worked with federal intelligence authorities over the weekend to identify and fix a critical security vulnerability discovered during a scheduled precautionary shutdown. The company said the flaw was confined to a capability enabled for less than 1% of its customer base, and there is no evidence it was ever exploited. A fix was developed and deployed during the shutdown window, with an additional protective layer applied across all environments.
The shutdown, lasting nine hours, was recommended after Kiteworks received intelligence about a potential imminent cyber attack. The company described the move as precautionary rather than a response to a confirmed breach, and the recommendation was lifted on 27 September 2026 once no anomalies were observed. Kiteworks has not released technical details about the vulnerability, and it does not yet have a public CVE identifier.
Kiteworks CISO Frank Balonis said asking customers to take production systems offline was not a decision made lightly, but that protecting customer data took priority over convenience. Customers are now advised to bring their Kiteworks systems back online.