Threat Intelligence

Kiteworks Patches Critical Flaw Found During Precautionary Shutdown

The Hacker News · 30 Sept 2026
Key Takeaway If a trusted vendor asks you to temporarily take systems offline as a precaution, treat it seriously and follow their guidance rather than assuming it's overcautious.

Kiteworks, formerly known as Accellion, has confirmed it worked with federal intelligence authorities over the weekend to identify and fix a critical security vulnerability discovered during a scheduled precautionary shutdown. The company said the flaw was confined to a capability enabled for less than 1% of its customer base, and there is no evidence it was ever exploited. A fix was developed and deployed during the shutdown window, with an additional protective layer applied across all environments.

The shutdown, lasting nine hours, was recommended after Kiteworks received intelligence about a potential imminent cyber attack. The company described the move as precautionary rather than a response to a confirmed breach, and the recommendation was lifted on 27 September 2026 once no anomalies were observed. Kiteworks has not released technical details about the vulnerability, and it does not yet have a public CVE identifier.

Kiteworks CISO Frank Balonis said asking customers to take production systems offline was not a decision made lightly, but that protecting customer data took priority over convenience. Customers are now advised to bring their Kiteworks systems back online.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.