Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day Targeting

Kiteworks Urges Global Customers to Shut Down Servers for (TL-2026-2670) is a high-severity zero-day vulnerability, first published 2026-09-25. It has no confirmed attribution, affects Kiteworks Kiteworks Platform (Secure File Sharing, Managed File, maps to 15 MITRE ATT&CK techniques (T1005, T1040, T1048), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2670

Threat ID
TL-2026-2670
Severity
HIGH
Status
ACTIVE
Category
ZERO_DAY
First published
2026-09-25
Last reviewed
2026-09-25
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
health, technology, education, automotive, government administration
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
12

Malware and tooling in Kiteworks Urges Global Customers to Shut Down Servers for

Malware and tooling: Clop, Fortra

Kiteworks, a secure file-sharing/managed-file-transfer (MFT) vendor formerly known as Accellion, told customers worldwide it received credible threat intelligence from federal intelligence/law-enforcement authorities that a threat actor may attempt to target Kiteworks systems, and asked all customers to take systems offline for a 6-9 hour precautionary window on September 26, 2026. Kiteworks says it has found no evidence of any actual compromise, no CVE has been assigned, and the current release (9.5.1) addresses all previously known vulnerabilities.

How Kiteworks Urges Global Customers to Shut Down Servers for works

On September 25, 2026, Kiteworks CISO Frank Balonis emailed customers stating the company had received 'credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,' and that the company had 'no indication that Kiteworks or our customers' systems have been compromised' -- characterizing the guidance explicitly as preventative rather than a response to a confirmed breach. The advisory, first reported by German outlet Heise and then confirmed directly to BleepingComputer, instructed customers to take their Kiteworks deployments offline during a regional window (e.g., 04:00-10:00 CET / 22:00 Fri-04:00 EDT in New York), spanning time zones from Australian Eastern Standard Time to Pacific Daylight Time. Kiteworks explicitly told customers to shut down even systems that are not directly internet-exposed, stating 'potential access paths' could not be ruled out. Self-managed customers (on-premises, AWS, or Azure) were told to perform the shutdown themselves; Kiteworks said it would shut down its own hosted customer instances on their behalf. The company's own press release confirmed its acquired subsidiary products -- Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, and 123FormBuilder -- are not affected by the advisory, implying the concern is scoped to the core Kiteworks platform (Secure File Sharing, Managed File Transfer, Email Protection, Secure Data Forms/Private Data Network, and Sensitive Content Communications). No CVE identifier, exploitation technique, affected component, or IOC was disclosed publicly. TechCrunch reported that CISA spokesperson Marco DiSandro declined to comment on the record and that the FBI also declined to comment when asked about the alert, and cited security researcher Kevin Beaumont's estimate of roughly 1,000 internet-facing Kiteworks instances (likely an undercount of total deployments). Multiple outlets noted this advisory lands against the backdrop of a well-documented pattern: Kiteworks' predecessor product, Accellion FTA, was mass-exploited via multiple zero-days by the Cl0p extortion actor (tracked as UNC2546) in December 2020-January 2021, and Cl0p has since repeated the same MFT zero-day extortion playbook against Fortra GoAnywhere (CVE-2023-0669, Feb 2023), Cleo Harmony/VLTrader/LexiCom (CVE-2024-55956, Dec 2024), and Oracle E-Business Suite (CVE-2025-61882, late 2025) -- none of which is confirmed to be connected to this advisory. Separately, Kiteworks itself disclosed and patched four vulnerabilities in its Secure Data Forms and Core components earlier in 2026: CVE-2026-23514 (Core access-control bypass, CVSS 8.8, fixed in 9.2.2), CVE-2026-23635 (Secure Data Forms unprotected credential transport, CVSS 6.5, fixed in 9.2.1), CVE-2026-24752 (Secure Data Forms reflected XSS, CVSS 8.2, fixed in 9.3.0), and CVE-2026-24753 (Secure Data Forms IDOR/authorization bypass, CVSS 6.5, fixed in 9.3.0). Kiteworks states the current 9.5.1 release addresses all of these; none is confirmed as the subject of the September 2026 shutdown advisory. Customer guidance issued alongside the shutdown included preserving authentication, application, web-server, endpoint, and network logs before restart; restricting administrative access; and reviewing for unusual file-transfer activity, unexpected authentication events, and unexplained privilege changes after systems come back online.

MITRE ATT&CK techniques used in TL-2026-2670

Collection

T1005 Data from Local System

Credential Access

T1040 Network Sniffing; T1557 Adversary-in-the-Middle

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Execution

T1059.007 JavaScript

Defense Evasion

T1078 Valid Accounts

Privilege Escalation

T1098 Account Manipulation

Initial Access

T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link

Persistence

T1505.003 Web Shell

Impact

T1565.001 Stored Data Manipulation; T1657 Financial Theft

Resource Development

T1588.005 Exploits

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Kiteworks Urges Global Customers to Shut Down Servers for

  • Kiteworks — Kiteworks Platform (Secure File Sharing, Managed File Transfer, Email Protection, Secure Data Forms / Private Data Network, Sensitive Content Communications)
    Vulnerable versions: Unspecified / unconfirmed - no affected component or version disclosed for the September 2026 advisory itself
    Fixed in: 9.5.1 (vendor-recommended current release)
  • Kiteworks — Kiteworks Core
    Vulnerable versions: 9.2.0; 9.2.1
    Fixed in: 9.2.2 (CVE-2026-23514)
  • Kiteworks — Kiteworks Secure Data Forms
    Vulnerable versions: prior to 9.2.1 (CVE-2026-23635); prior to 9.3.0 (CVE-2026-24752, CVE-2026-24753)
    Fixed in: 9.2.1; 9.3.0
  • Kiteworks — Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, 123FormBuilder (Kiteworks-owned subsidiary products)
    Fixed in: Not applicable - vendor explicitly confirmed these are not affected by this advisory

Remediation for Kiteworks Urges Global Customers to Shut Down Servers for

Patches

  • Kiteworks platform 9.5.1 (current release; vendor states it addresses all previously known vulnerabilities, including CVE-2026-23514, CVE-2026-23635, CVE-2026-24752, and CVE-2026-24753)

Immediate actions

  • Complete the vendor-directed regional shutdown window and confirm restart only after the window closes
  • Preserve authentication, application, web-server, endpoint, and network logs prior to shutdown and after restart
  • Upgrade all Kiteworks deployments to version 9.5.1 or later before bringing systems back online
  • After restart, review logs for unusual file-transfer activity, unexpected authentication events, and unexplained privilege or role changes
  • Restrict administrative access to Kiteworks management interfaces during and immediately after the window
  • Shut down Kiteworks systems even if they are not directly internet-exposed, per vendor guidance that alternate access paths could not be ruled out

Workarounds

  • Perform the vendor-specified 6-9 hour precautionary shutdown even for systems not directly reachable from the internet
  • Self-managed customers (on-premises, AWS, or Azure) must execute the shutdown themselves; Kiteworks-hosted customers have it performed on their behalf and require no customer action

Longer-term hardening

  • Treat internet-facing managed file transfer (MFT) and secure file-sharing platforms as high-value zero-day targets given the repeated pattern (Accellion FTA, MOVEit, GoAnywhere, Cleo, Oracle EBS) and prioritize rapid patch SLAs for them
  • Segment MFT/secure file-sharing infrastructure from the broader internal network to limit blast radius from a future zero-day
  • Deploy behavioral monitoring/EDR around MFT platforms specifically tuned for anomalous file-transfer volume, authentication anomalies, and privilege changes
  • Subscribe to the Kiteworks GitHub security-advisories feed and vendor Trust Center for real-time patch/advisory notifications
  • Reduce unnecessary internet exposure of MFT admin interfaces; Kevin Beaumont's census of ~1,000 internet-facing Kiteworks instances underscores the available attack surface

Timeline of Kiteworks Urges Global Customers to Shut Down Servers for

  • Cl0p (tracked as UNC2546) begins mass-exploiting multiple zero-day vulnerabilities in Accellion FTA - Kiteworks' predecessor product - in a campaign that continued into January 2021 and is cited by multiple outlets as the historical precedent for this advisory.
  • CVE-2026-23514, an access-control bypass in Kiteworks Core (CVSS 8.8) allowing authenticated users to view unauthorized content, is published; fixed in Kiteworks Core 9.2.2.
  • CVE-2026-23635, an unprotected-credential-transport flaw in Kiteworks Secure Data Forms (CVSS 6.5), is published; fixed in version 9.2.1.
  • CVE-2026-24752 (reflected XSS, CVSS 8.2) and CVE-2026-24753 (IDOR/authorization bypass) in Kiteworks Secure Data Forms are published; both fixed in version 9.3.0.
  • TechCrunch reports that CISA spokesperson Marco DiSandro and the FBI both declined to comment on the record about the threat alert to Kiteworks.
  • Kiteworks publishes an official press release confirming current release 9.5.1 addresses all known vulnerabilities and that subsidiary products (Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, 123FormBuilder) are not affected.
  • Kiteworks CISO Frank Balonis emails customers stating the company received credible threat intelligence from federal intelligence/law-enforcement authorities that a threat actor may attempt to target Kiteworks systems, and schedules a precautionary shutdown window.
  • German outlet Heise first reports that Kiteworks is telling customers to shut down systems over a possible zero-day; Kiteworks confirms the advisory directly to BleepingComputer.
  • The coordinated 6-9 hour precautionary shutdown window executes globally (e.g., 04:00-10:00 CET in Central Europe, 22:00 Fri-04:00 EDT in New York), spanning time zones from Australian Eastern Standard Time to Pacific Daylight Time.

Sources cited for Kiteworks Urges Global Customers to Shut Down Servers for

More in zero day

Detection coverage for TL-2026-2670

As of 2026-09-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2670 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats