Security News

Kiteworks Restores Service After Precautionary Shutdown Uncovers Critical Flaw

CyberScoop · 30 Sept 2026
Key Takeaway Australian SMBs using Kiteworks, particularly Advanced Forms, should update to release 9.5.1 promptly and review vendor security advisories for further guidance.

Kiteworks, a provider of secure file transfer and data-sharing tools, has told customers they can resume normal operations after taking systems offline over the weekend in response to what it described as "credible threat intelligence" from federal authorities. The company said continuous monitoring found no signs of abnormal activity by Sunday.

During the shutdown, Kiteworks discovered a previously unknown critical vulnerability in Advanced Forms, a secure data collection tool used by fewer than 1% of its customers (around 50 organisations). Its other products, including file collaboration, file transfer, email encryption and managed file transfer, were not affected. The company said it developed and deployed a fix during the shutdown window and has seen no evidence the flaw was exploited. All known issues are addressed in release 9.5.1, which Kiteworks recommends customers update to.

Company leaders said the decision to ask customers to take production systems offline was not made lightly, but reflected a preference for acting on credible warnings rather than waiting for proof of an attack. Kiteworks, formerly known as Accellion, rebranded in 2021 after a vulnerability in its legacy file transfer appliance was exploited by an extortion gang in a wave of attacks on file transfer products.

file transfer security vulnerability Kiteworks incident response data protection

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.