Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day Targeting
Kiteworks Urges Global Customers to Shut Down Servers for (TL-2026-2670) is a high-severity zero-day vulnerability, first published 2026-09-25. It has no confirmed attribution, affects Kiteworks Kiteworks Platform (Secure File Sharing, Managed File, maps to 15 MITRE ATT&CK techniques (T1005, T1040, T1048), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-2670
- Threat ID
- TL-2026-2670
- Severity
- HIGH
- Status
- ACTIVE
- Category
- ZERO_DAY
- First published
- 2026-09-25
- Last reviewed
- 2026-09-25
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- health, technology, education, automotive, government administration
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Kiteworks Urges Global Customers to Shut Down Servers for
Malware and tooling: Clop, Fortra
Kiteworks, a secure file-sharing/managed-file-transfer (MFT) vendor formerly known as Accellion, told customers worldwide it received credible threat intelligence from federal intelligence/law-enforcement authorities that a threat actor may attempt to target Kiteworks systems, and asked all customers to take systems offline for a 6-9 hour precautionary window on September 26, 2026. Kiteworks says it has found no evidence of any actual compromise, no CVE has been assigned, and the current release (9.5.1) addresses all previously known vulnerabilities.
How Kiteworks Urges Global Customers to Shut Down Servers for works
On September 25, 2026, Kiteworks CISO Frank Balonis emailed customers stating the company had received 'credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,' and that the company had 'no indication that Kiteworks or our customers' systems have been compromised' -- characterizing the guidance explicitly as preventative rather than a response to a confirmed breach. The advisory, first reported by German outlet Heise and then confirmed directly to BleepingComputer, instructed customers to take their Kiteworks deployments offline during a regional window (e.g., 04:00-10:00 CET / 22:00 Fri-04:00 EDT in New York), spanning time zones from Australian Eastern Standard Time to Pacific Daylight Time. Kiteworks explicitly told customers to shut down even systems that are not directly internet-exposed, stating 'potential access paths' could not be ruled out. Self-managed customers (on-premises, AWS, or Azure) were told to perform the shutdown themselves; Kiteworks said it would shut down its own hosted customer instances on their behalf. The company's own press release confirmed its acquired subsidiary products -- Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder -- are not affected by the advisory, implying the concern is scoped to the core Kiteworks platform (Secure File Sharing, Managed File Transfer, Email Protection, Secure Data Forms/Private Data Network, and Sensitive Content Communications). No CVE identifier, exploitation technique, affected component, or IOC was disclosed publicly. TechCrunch reported that CISA spokesperson Marco DiSandro declined to comment on the record and that the FBI also declined to comment when asked about the alert, and cited security researcher Kevin Beaumont's estimate of roughly 1,000 internet-facing Kiteworks instances (likely an undercount of total deployments). Multiple outlets noted this advisory lands against the backdrop of a well-documented pattern: Kiteworks' predecessor product, Accellion FTA, was mass-exploited via multiple zero-days by the Cl0p extortion actor (tracked as UNC2546) in December 2020-January 2021, and Cl0p has since repeated the same MFT zero-day extortion playbook against Fortra GoAnywhere (CVE-2023-0669, Feb 2023), Cleo Harmony/VLTrader/LexiCom (CVE-2024-55956, Dec 2024), and Oracle E-Business Suite (CVE-2025-61882, late 2025) -- none of which is confirmed to be connected to this advisory. Separately, Kiteworks itself disclosed and patched four vulnerabilities in its Secure Data Forms and Core components earlier in 2026: CVE-2026-23514 (Core access-control bypass, CVSS 8.8, fixed in 9.2.2), CVE-2026-23635 (Secure Data Forms unprotected credential transport, CVSS 6.5, fixed in 9.2.1), CVE-2026-24752 (Secure Data Forms reflected XSS, CVSS 8.2, fixed in 9.3.0), and CVE-2026-24753 (Secure Data Forms IDOR/authorization bypass, CVSS 6.5, fixed in 9.3.0). Kiteworks states the current 9.5.1 release addresses all of these; none is confirmed as the subject of the September 2026 shutdown advisory. Customer guidance issued alongside the shutdown included preserving authentication, application, web-server, endpoint, and network logs before restart; restricting administrative access; and reviewing for unusual file-transfer activity, unexpected authentication events, and unexplained privilege changes after systems come back online.
MITRE ATT&CK techniques used in TL-2026-2670
Collection
Credential Access
T1040 Network Sniffing; T1557 Adversary-in-the-Middle
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Execution
Defense Evasion
Privilege Escalation
Initial Access
T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link
Persistence
Impact
T1565.001 Stored Data Manipulation; T1657 Financial Theft
Resource Development
Reconnaissance
Affected products and versions in Kiteworks Urges Global Customers to Shut Down Servers for
- Kiteworks — Kiteworks Platform (Secure File Sharing, Managed File Transfer, Email Protection, Secure Data Forms / Private Data Network, Sensitive Content Communications)
Vulnerable versions: Unspecified / unconfirmed - no affected component or version disclosed for the September 2026 advisory itself
Fixed in: 9.5.1 (vendor-recommended current release) - Kiteworks — Kiteworks Core
Vulnerable versions: 9.2.0; 9.2.1
Fixed in: 9.2.2 (CVE-2026-23514) - Kiteworks — Kiteworks Secure Data Forms
Vulnerable versions: prior to 9.2.1 (CVE-2026-23635); prior to 9.3.0 (CVE-2026-24752, CVE-2026-24753)
Fixed in: 9.2.1; 9.3.0 - Kiteworks — Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, 123FormBuilder (Kiteworks-owned subsidiary products)
Fixed in: Not applicable - vendor explicitly confirmed these are not affected by this advisory
Remediation for Kiteworks Urges Global Customers to Shut Down Servers for
Patches
- Kiteworks platform 9.5.1 (current release; vendor states it addresses all previously known vulnerabilities, including CVE-2026-23514, CVE-2026-23635, CVE-2026-24752, and CVE-2026-24753)
Immediate actions
- Complete the vendor-directed regional shutdown window and confirm restart only after the window closes
- Preserve authentication, application, web-server, endpoint, and network logs prior to shutdown and after restart
- Upgrade all Kiteworks deployments to version 9.5.1 or later before bringing systems back online
- After restart, review logs for unusual file-transfer activity, unexpected authentication events, and unexplained privilege or role changes
- Restrict administrative access to Kiteworks management interfaces during and immediately after the window
- Shut down Kiteworks systems even if they are not directly internet-exposed, per vendor guidance that alternate access paths could not be ruled out
Workarounds
- Perform the vendor-specified 6-9 hour precautionary shutdown even for systems not directly reachable from the internet
- Self-managed customers (on-premises, AWS, or Azure) must execute the shutdown themselves; Kiteworks-hosted customers have it performed on their behalf and require no customer action
Longer-term hardening
- Treat internet-facing managed file transfer (MFT) and secure file-sharing platforms as high-value zero-day targets given the repeated pattern (Accellion FTA, MOVEit, GoAnywhere, Cleo, Oracle EBS) and prioritize rapid patch SLAs for them
- Segment MFT/secure file-sharing infrastructure from the broader internal network to limit blast radius from a future zero-day
- Deploy behavioral monitoring/EDR around MFT platforms specifically tuned for anomalous file-transfer volume, authentication anomalies, and privilege changes
- Subscribe to the Kiteworks GitHub security-advisories feed and vendor Trust Center for real-time patch/advisory notifications
- Reduce unnecessary internet exposure of MFT admin interfaces; Kevin Beaumont's census of ~1,000 internet-facing Kiteworks instances underscores the available attack surface
Timeline of Kiteworks Urges Global Customers to Shut Down Servers for
- Cl0p (tracked as UNC2546) begins mass-exploiting multiple zero-day vulnerabilities in Accellion FTA - Kiteworks' predecessor product - in a campaign that continued into January 2021 and is cited by multiple outlets as the historical precedent for this advisory.
- CVE-2026-23514, an access-control bypass in Kiteworks Core (CVSS 8.8) allowing authenticated users to view unauthorized content, is published; fixed in Kiteworks Core 9.2.2.
- CVE-2026-23635, an unprotected-credential-transport flaw in Kiteworks Secure Data Forms (CVSS 6.5), is published; fixed in version 9.2.1.
- CVE-2026-24752 (reflected XSS, CVSS 8.2) and CVE-2026-24753 (IDOR/authorization bypass) in Kiteworks Secure Data Forms are published; both fixed in version 9.3.0.
- TechCrunch reports that CISA spokesperson Marco DiSandro and the FBI both declined to comment on the record about the threat alert to Kiteworks.
- Kiteworks publishes an official press release confirming current release 9.5.1 addresses all known vulnerabilities and that subsidiary products (Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, 123FormBuilder) are not affected.
- Kiteworks CISO Frank Balonis emails customers stating the company received credible threat intelligence from federal intelligence/law-enforcement authorities that a threat actor may attempt to target Kiteworks systems, and schedules a precautionary shutdown window.
- German outlet Heise first reports that Kiteworks is telling customers to shut down systems over a possible zero-day; Kiteworks confirms the advisory directly to BleepingComputer.
- The coordinated 6-9 hour precautionary shutdown window executes globally (e.g., 04:00-10:00 CET in Central Europe, 22:00 Fri-04:00 EDT in New York), spanning time zones from Australian Eastern Standard Time to Pacific Daylight Time.
Sources cited for Kiteworks Urges Global Customers to Shut Down Servers for
- Kiteworks urges 6-hour server shutdown over potential zero-day attacks
- Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack
- Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
- Kiteworks Issues Precautionary Shutdown Advisory for Customers Following Credible Threat Intelligence From Federal Intelligence Authorities
- Kiteworks zero-day warning prompts shutdown advice
- Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat
- Kiteworks Customers Told to Shut Down Servers Over Possible Zero-Day Attack
- GHSA-qmv7-28g4-hx9x - Kiteworks Secure Data Forms IDOR (CVE-2026-24753)
- GHSA-9hw2-6qp4-3v8f - Kiteworks Secure Data Forms unprotected credential transport (CVE-2026-23635)
- NVD - CVE-2026-24752 (Kiteworks Secure Data Forms reflected XSS)
- CVE-2026-24753 detail - Kiteworks Secure Data Forms Authorization Bypass
- CVE-2026-23635 - Kiteworks Information Disclosure Flaw
- Kiteworks Core Access Control Vulnerability (CVE-2026-23514)
More in zero day
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible Zero-Day Attack
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense Industry
- European Parliament Member Investigating Pegasus Spyware Hacked With Pegasus (PWNYOURHOME Zero-Click Exploit Chain)
Detection coverage for TL-2026-2670
As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2670 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.