← All stories
● Covered by 5 sources · 8 reportsMedium impact1 negative7 neutral

Kiteworks Urges Customers to Shut Down Servers Due to Imminent Cyberattack Threat

🔄 Updated 21h ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Kiteworks alerted customers about an imminent cyberattack threat.
  • Law enforcement provided credible threat intelligence.
  • Customers were advised to shut down systems as a precaution.
  • The threat may involve unknown zero-day vulnerabilities.
  • Customers were advised to shut down systems during a six-hour window on Saturday.
  • Frank Balonis, CISO at Kiteworks, confirmed the threat intelligence.
  • All known vulnerabilities are addressed in Kiteworks' current release, 9.5.1.
  • German technology publication Heise reported on the Kiteworks warning.
  • Central European customers were instructed to shut down systems from 4:00 a.m. to 10:00 a.m. on Saturday, September 26.
  • New York customers had a shutdown window from 10:00 p.m. Friday to 4:00 a.m. Saturday.
  • Kiteworks was formerly known as Accellion.
  • Customers were advised to shut down systems for nine hours.
  • The shutdown recommendation was lifted on Sunday.
  • The vulnerability affects the Advanced Forms product.
  • The vulnerability affects fewer than 1% of customers, under 50 organizations.
  • There is no evidence of exploitation of the vulnerability.
  • Kiteworks operates a Private Content Network (PCN).
  • Kiteworks' Private Data Network has over 100 million end-users.
  • Kiteworks brought all hosted customer systems back online on Monday, September 27.
  • Kiteworks found no evidence of compromise or suspicious activity.
  • Kiteworks worked with federal intelligence authorities over the weekend.
  • Kiteworks discovered a previously unknown critical vulnerability.
  • Kiteworks developed and deployed a fix during the shutdown window.
  • Kiteworks applied an additional protective layer across all environments.
  • Other Kiteworks products are not affected by the flaw.
  • The shutdown recommendation was lifted on September 27, 2026.
  • Kiteworks released security updates for 126 vulnerabilities.
  • A critical code injection flaw, CVE-2026-54154, affects the Email Protection Gateway (EPG).
  • The EPG vulnerability allows unauthenticated remote code execution and administrative control.
  • The EPG vulnerability impacts all EPG releases before version 9.4.1.
  • Kiteworks fixed 11 critical authentication bypass, account takeover, XSS, and access control flaws.
  • The max-severity vulnerability was reported via Kiteworks' YesWeHack bug bounty program.

Precautionary Shutdown Advised

Kiteworks, a technology company specializing in large file transfers, has urged its customers to shut down their systems. This recommendation follows credible threat intelligence received from law enforcement, indicating a potential cyberattack targeting Kiteworks systems for customers.

Imminent Threat of Zero-Day Exploits

The company's chief information security officer, Frank Balonis, stated that the advisory is preventative and not a response to a confirmed breach. Kiteworks expressed concern about the exploitation of currently unknown vulnerabilities, known as zero-day flaws, which could be exploited before patches are available.

Customer Notification and Recommendations

Kiteworks notified customers directly, recommending a precautionary shutdown window. The company also stated that all known vulnerabilities have been fixed in its latest software release, version 9.5.1, which it advises all customers to use. The specific law enforcement agency or hacking group involved was not disclosed.

Potential Impact

The exact number of affected customers is unclear, but Kiteworks' website indicates thousands of clients across various sectors including healthcare, technology, education, automotive, and government. The shutdown recommendation aims to protect these customers from potential improper access.

Updates

🕒 2026-10-01 · new reporting from BleepingComputer
  • Kiteworks released security updates for 126 vulnerabilities.
  • A critical code injection flaw, CVE-2026-54154, affects the Email Protection Gateway (EPG).
  • The EPG vulnerability allows unauthenticated remote code execution and administrative control.
  • The EPG vulnerability impacts all EPG releases before version 9.4.1.
  • Kiteworks fixed 11 critical authentication bypass, account takeover, XSS, and access control flaws.
  • The max-severity vulnerability was reported via Kiteworks' YesWeHack bug bounty program.
🕒 2026-09-29 · new reporting from The Hacker News
  • Kiteworks worked with federal intelligence authorities over the weekend.
  • Kiteworks discovered a previously unknown critical vulnerability.
  • Kiteworks developed and deployed a fix during the shutdown window.
  • Kiteworks applied an additional protective layer across all environments.
  • Other Kiteworks products are not affected by the flaw.
  • The shutdown recommendation was lifted on September 27, 2026.
🕒 2026-09-29 · new reporting from BleepingComputer
  • Kiteworks operates a Private Content Network (PCN).
  • Kiteworks' Private Data Network has over 100 million end-users.
  • Kiteworks brought all hosted customer systems back online on Monday, September 27.
  • Kiteworks found no evidence of compromise or suspicious activity.
🕒 2026-09-28 · new reporting from SecurityWeek
  • The shutdown recommendation was lifted on Sunday.
  • The vulnerability affects the Advanced Forms product.
  • The vulnerability affects fewer than 1% of customers, under 50 organizations.
  • There is no evidence of exploitation of the vulnerability.
🕒 2026-09-26 · new reporting from The Hacker News
  • Kiteworks was formerly known as Accellion.
  • Customers were advised to shut down systems for nine hours.
🕒 2026-09-26 · new reporting from BleepingComputer
  • German technology publication Heise reported on the Kiteworks warning.
  • Central European customers were instructed to shut down systems from 4:00 a.m. to 10:00 a.m. on Saturday, September 26.
  • New York customers had a shutdown window from 10:00 p.m. Friday to 4:00 a.m. Saturday.
🕒 2026-09-25 · new reporting from The Record
  • Customers were advised to shut down systems during a six-hour window on Saturday.
  • Frank Balonis, CISO at Kiteworks, confirmed the threat intelligence.
  • All known vulnerabilities are addressed in Kiteworks' current release, 9.5.1.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Kiteworks released security updates addressing 126 vulnerabilities, including a critical code injection flaw (CVE-2026-54154) in its Email Protection Gateway (EPG) solution. This vulnerability allowed unauthenticated remote code execution and potential administrative control of affected appliances, impacting all EPG releases before version 9.4.1.

Kiteworks identified and patched a critical security vulnerability during a nine-hour precautionary shutdown initiated due to intelligence about a potential cyber attack. The flaw affected less than 1% of its customer base and there is no evidence of exploitation.

Kiteworks, a secure file-sharing company, patched a critical vulnerability and lifted a system shutdown advisory after federal intelligence warned of a potential cyberattack. The company found no evidence of compromise and brought all hosted customer systems back online. This event highlights the ongoing threat to file-sharing platforms, which are frequently targeted for sensitive data.

Kiteworks instructed customers to shut down servers over the weekend due to a severe vulnerability in its Advanced Forms product, based on credible threat intelligence from federal authorities. The company has since lifted the shutdown recommendation, stating the vulnerability affects less than 1% of customers and there is no evidence of exploitation.

Kiteworks, formerly Accellion, urged its customers to shut down their systems for nine hours over a weekend after receiving credible threat intelligence about a potential cyber attack. This advisory is a precautionary measure, as the company has not found evidence of compromise, and recommends customers update to software release 9.5.1.

Kiteworks advised customers worldwide to shut down their servers for six hours due to credible threat intelligence indicating a potential cyberattack. This precautionary measure aims to protect against possible zero-day exploits, though no breach has been confirmed.

Kiteworks has urged its customers to temporarily shut down their systems over a weekend after receiving credible threat intelligence from federal agencies about potential cyberattacks targeting some Kiteworks systems. This advisory is a precautionary measure, as the company is not aware of any confirmed compromise, but it suggests a significant, unpatched vulnerability may exist.

Kiteworks advised its customers to shut down their systems after receiving credible threat intelligence from law enforcement about an imminent cyberattack. The company recommended a precautionary shutdown to protect against potential zero-day exploits, though no compromise has been confirmed.