Skip to content
TrustList
News

Kiteworks told self-hosting customers to shut their servers down on 26 September over a possible attack

Editorial

By TrustList Editorial

The secure file-sharing vendor cited federal threat intelligence of a possible attack and asked self-managed customers to power down for a window on Saturday 26 September. It reports no compromise and says release 9.5.1 fixes every known flaw.

About Kiteworks told self-hosting customers to shut their servers down on 26 September over a possible attack

Kiteworks told self-hosting customers to shut their servers down on 26 September over a possible attack

25 September 2026 — Kiteworks, which sells a secure file-sharing and managed file-transfer platform, asked customers on 25 September 2026 to shut down their Kiteworks systems for a window on Saturday 26 September. The company says it received "credible threat intelligence from federal intelligence authorities" that a threat actor might target some Kiteworks systems. It also says it has no indication that its own or its customers' systems have been compromised, and calls the advisory preventative.

Not yet independently verified. That an attack was expected rests on Kiteworks’ own account; the intelligence it cites has not been published, and no vulnerability or CVE has been named. Kiteworks’ release describes a nine-hour window; BleepingComputer and Sophos, citing the customer email, describe six hours, 02:00 to 08:00 UTC. We have not seen the email. We will update this when it can be confirmed, and remove this note.

What Kiteworks asked for

  • Customers who run Kiteworks themselves, on their own servers or in their own AWS or Azure accounts, were asked to shut the systems down for the window.
  • Customers on Kiteworks-hosted systems did not need to act; the company said it would handle the shutdown.
  • Kiteworks says release 9.5.1 contains fixes for all known vulnerabilities.
  • The company says the advisory does not affect its subsidiaries, which it lists as Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai and 123FormBuilder.

The window has now passed. As of 27 September we found no follow-up from Kiteworks saying whether an attack took place, or whether a new fix is coming.

Why this matters

Kiteworks is the successor to Accellion, whose file-transfer appliance was exploited by the Clop extortion group in late 2020 and early 2021, as The Hacker News recalls. File-transfer platforms hold exactly the documents extortion groups want. A vendor asking customers to switch off production systems on a warning, before any patch or CVE exists, is unusual, and suggests the vendor could not rule out an unfixed flaw.

Who is affected

Organisations that exchange sensitive files with clients, regulators or suppliers through Kiteworks, especially those running it themselves. That includes law firms, healthcare providers, financial services and public-sector bodies, and the managed providers that host Kiteworks for them.

What to do

  • Confirm every Kiteworks system you run, or a provider runs for you, is on 9.5.1.
  • If you run it yourself and did not shut down, or brought it back early, review logs from 25 September onwards for unusual logins, new accounts and large downloads.
  • Watch Kiteworks' support channels for a follow-up advisory, a CVE or a new release, and apply it as soon as it appears.
  • Limit exposure while the position is unclear: restrict the admin interface to known addresses, and review which external users hold active accounts.
  • If the platform is provided to you by a partner, ask in writing whether the shutdown was carried out and what version is installed.

Sources