www.securityweek.com 28 Sept 2026, 09:44 UTC

Kiteworks Urges Shutdown After Severe Advanced Forms Flaw Discovered

Kiteworks Urges Shutdown After Severe Advanced Forms Flaw Discovered
CyberSIXT Evidence Panel Source marked as original reporting

KITEWORKS , the secure data-sharing provider formerly known as Accellion, advised customers to shut down on-premises and customer-hosted servers for nine hours after receiving credible threat intelligence from federal authorities. The precaution was prompted by a severe vulnerability in its Advanced Forms secure data-collection product, which is enabled for fewer than 1% of customers — fewer than 50 organisations, according to a customer email shared on Reddit.

Kiteworks said its other products, including file transfer, file collaboration, email encryption, APIs, managed file transfer and the DPE, were unaffected.

The company lifted the shutdown recommendation on Sunday and said customers could bring their systems back online. Customers running self-hosted Advanced Forms were told to contact Kiteworks Support, while systems hosted by Kiteworks had been restored. Kiteworks said it had no evidence that the vulnerability had been exploited or that its own or customers’ systems had been compromised, making the advisory preventative rather than a response to a confirmed breach.

The company said it was working with industry partners, including Mandiant, and that all known vulnerabilities had been addressed in its current release, 9.5.1. It continues to recommend that customers run the latest version.

View full article

Article by CyberSIXT