Cybersecurity Research

Kiteworks Warns Customers of Imminent Attack, Urges Precautionary Server Shutdowns

Sophos · 25 Sept 2026
Key Takeaway If you use Kiteworks, follow the vendor's official guidance immediately and consider temporarily taking affected servers offline until more information is confirmed.

Kiteworks, formerly known as Acellion, has emailed customers warning that law enforcement notified the company of an “imminent” cyberattack targeting its systems. The company said the attack may involve exploitation of a zero-day vulnerability, meaning a flaw that is not yet publicly known or patched.

As a precautionary measure, Kiteworks reportedly advised customers to shut down their servers between 02:00 and 08:00 UTC on September 26, or sooner if possible. Sophos' Counter Threat Unit (CTU) research team has acknowledged the reports and is recommending that affected organisations follow Kiteworks' guidance directly rather than wait for further public detail.

At this stage, specific technical details about the vulnerability or attack method have not been disclosed publicly. Businesses using Kiteworks products should treat vendor communications as the authoritative source of instructions during this period.

Kiteworks zero-day vulnerability incident response

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.