[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftm8stcDVV_92Ruxqlv76WPAjlJ40KTxy77SuAx-N01g":3},{"article":4,"iocs":46},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"166c86ec-c318-4900-8ed9-4de457ee82e4","Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability","kiteworks-urges-server-shutdown-finds-advanced-forms-vulnerability-3a00f8","The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised. The post Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability appeared first on SecurityWeek.","Secure data sharing provider Kiteworks instructed customers to shut down servers due to credible threat intelligence about a zero-day vulnerability in its Advanced Forms product. The company has since lifted the recommendation, stating there is no evidence of compromise. The vulnerability affected less than 1% of customers, and Kiteworks is collaborating with partners like Mandiant to investigate the threat.","Kiteworks advises server shutdown due to zero-day vulnerability in Advanced Forms.","Secure data sharing solutions provider Kiteworks (formerly Accellion) over the weekend instructed customers to shut down their servers in response to credible threat intelligence from federal authorities. In a communication to customers on Friday, the company advised a “nine-hour precautionary shutdown” of on-premises and customer-hosted instances, noting that hackers may target zero-day vulnerabilities in its products. On Sunday, the company announced it had lifted the shutdown recommendation for all customers, and that they could bring their systems back online. “Customers with self-hosted Advanced Forms should contact Customer Support for assistance. All systems Kiteworks hosts on customers’ behalf have been brought back up and are operating normally,” the company said. While Kiteworks’s announcement did not detail the threat, the company said in emails to its customers that a severe vulnerability in its Advanced Forms secure data collection product triggered the shutdown. “Advanced Forms is enabled for fewer than 1% of our customers, under 50 organizations, and the vulnerability is confined to that product only. All other products, including the DPE, file collaboration, file transfer, email encryption, APIs, and MFT, are unaffected,” a copy of the email shared on Reddit reads.Advertisement. Scroll to continue reading. The company said it had no evidence the security defect was exploited and that it was working with “industry partners, including Mandiant, to share intelligence about the threat”. Kiteworks CISO Frank Balonis said: “Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems. Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities. We have no indication that Kiteworks or our customers’ systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach. Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version.” Related: Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the Plug Related: Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks Related: OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure Related: ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data ExfiltrationRoundcube Webmail Vulnerability in Attackers’ CrosshairsKontext Security Emerges With $4 Million for AI Agent Runtime ControlsAI-Powered Campaign Targets Hundreds of Online RetailersSolarWinds Patches Critical RCE Flaws in Observability Self-HostedAstrana Health Data Breach Impacts Private, Confidential InformationCritical WordPress Vulnerability Exploited Immediately After Disclosure Latest News Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksChina and US Agree to Establish AI Safety Channel and Continue Trade and Military TalksNew x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingOpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior DisclosureIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility ExposureNorth Korea Suspected in $351 Million Bitget Crypto HeistCISA Election Security Plan Flags Patching Barriers, Voter Database Attacks Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveDoppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.Delinea has appointed Timothy Regan as Chief Financial Officer.Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.More People On The MoveExpert Insights Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fkiteworks-urges-server-shutdown-finds-advanced-forms-vulnerability\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F12\u002Ffile-transfer-Moveit.jpg","2026-09-28T09:44:27+00:00","2026-09-28T10:00:08.138159+00:00",8,[18,21,24,26],{"name":19,"type":20},"Advanced Forms","product",{"name":22,"type":23},"Kiteworks","vendor",{"name":25,"type":23},"Accellion",{"name":27,"type":23},"Mandiant","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":28,"icon":30,"name":31,"slug":32},null,"Vulnerabilities","vulnerabilities",[34,39,41],{"category":35},{"id":36,"icon":30,"name":37,"slug":38},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":40},{"id":28,"icon":30,"name":31,"slug":32},{"category":42},{"id":43,"icon":30,"name":44,"slug":45},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]