CTIPilot

Kiteworks Advanced Forms

product · product:kiteworks-advanced-forms

Coverage timeline
1
first 2026-09-26 → last 2026-09-26
Peak priority
notable
1 notable
Sources cited
7
7 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

Releases covered
Kiteworks Advanced Forms
ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-26/kiteworks-precautionary-shutdown-imminent-zero-day-warning · ATT&CK page ↗

Story timeline

  1. 2026-09-26Kiteworks (formerly Accellion) tells customers worldwide to shut down every server for six hours after 'credible' law-enforcement intelligence of an imminent attack, no CVE assigned
    active-threatsA secure-file-transfer vendor with government customers tells its entire customer base to unplug production systems this weekend

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (14%)
  • heise.de1 (14%)
  • kiteworks.com1 (14%)
  • security-hub.ncsc.admin.ch1 (14%)
  • techcrunch.com1 (14%)
  • therecord.media1 (14%)
  • wid.cert-bund.de1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Kiteworks Advanced Forms (1)

2026-09-26 · view entry permalink →

NOTABLEupdatedNATOB2

Kiteworks (formerly Accellion) tells customers worldwide to shut down every server for six hours after 'credible' law-enforcement intelligence of an imminent attack, no CVE assigned

Kiteworks (a secure managed-file-transfer and confidential-communications platform rebranded from Accellion in 2021, marketed to government agencies, financial institutions and enterprises) emailed customers worldwide on 2026-09-25 urging a precautionary six-hour shutdown of every Kiteworks system, staggered by timezone; the Central European window falls 04:00–10:00 CEST on Saturday 2026-09-26, a timezone Switzerland shares (Heise Online, 2026-09-25). CISO Frank Balonis told Heise Online the company "received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend" (Heise Online, 2026-09-25), and recommended shutting systems down even where they are not directly internet-facing, since the possible access route is unconfirmed. No CVE has been assigned, and Kiteworks states plainly it is "not aware of any compromise of Kiteworks systems" and that "all known vulnerabilities are addressed in our current release, 9.5.1" (BleepingComputer, 2026-09-25); the advisory is preventative, not a confirmed-breach response. Researcher Kevin Beaumont's Shodan search found roughly a thousand internet-facing Kiteworks instances, though TechCrunch notes the count is likely an overcount of actually-affected customer systems (TechCrunch, 2026-09-25), and watchTowr's Jake Knott called the request itself unusual: "nobody requests that their entire customer base unplug production systems over the weekend because of a hunch" (The Record, 2026-09-25).

The precedent class is exactly the one that matters for public-sector defenders: BleepingComputer notes that the Clop extortion gang "has a long history of targeting enterprise platforms in data-theft attacks," naming Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer as past victims of that pattern (BleepingComputer, 2026-09-25); no actor has been named or confirmed for this specific warning by Kiteworks, the FBI, or CISA. Kiteworks itself was formerly Accellion, whose FTA product was the subject of exactly this kind of zero-day mass exploitation in December 2020, when a Clop-linked group stole data from dozens of high-profile organizations (The Record, 2026-09-25).

We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend. We strongly recommend you shut down your Kiteworks system for six hours

Kiteworks CISO Frank Balonis, via Heise Online

We are not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach

All known vulnerabilities are addressed in our current release, 9.5.1, and we continue to recommend customers run the latest version.

Kiteworks, statement to BleepingComputer

There is no known CVE, patch, or additional technical details available – but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch.

Jake Knott, watchTowr, via The Record (Recorded Future News)

As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online.

Kiteworks 2026-09-27

We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach.

Frank Balonis, CISO, Kiteworks

"An attacker can exploit a vulnerability in Kiteworks Advanced Forms to carry out an unspecified attack." # translated from German

BSI CERT-Bund (WID-SEC-2026-3602) 2026-09-27
Updaterun 2026-09-29T0405Z-intelprioritytagsaffected_productssourcesevidencesourcing_noteactionsbody

Kiteworks' own press release states the recommended shutdown window was nine hours, not the six hours this entry originally reported from press coverage of the initial advisory; the vendor's own page is the more authoritative figure and the discrepancy is noted here rather than silently corrected in the original paragraph, since neither this entry's original sources nor Kiteworks' own later statement explain the difference. Kiteworks updated its own press release on 2026-09-27 to state the shutdown recommendation is lifted: "As of September 27th, the shutdown recommendation is now lifted for all customers. If you have not already restarted, you may bring your Kiteworks system back online" (Kiteworks, 2026-09-27). CISO Frank Balonis reiterated the company found no evidence of compromise: "We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach" (Kiteworks, 2026-09-27). Germany's BSI published advisory WID-SEC-2026-3602 on 2026-09-27, citing the Kiteworks press release as its source and naming the vulnerable component for the first time: "An attacker can exploit a vulnerability in Kiteworks Advanced Forms to carry out an unspecified attack" (translated from German) (BSI CERT-Bund, 2026-09-27), listing Advanced Forms versions below 9.5.1 as affected and fixed in 9.5.1; NCSC Switzerland's Cyber Security Hub advisory was updated the same day with the lifted-shutdown status. No CVE has been assigned to date, and the BSI record carries no vulnerability-class (CWE) description beyond "unspecified attack": genuinely thin technical detail from the vendor side even now, not withheld by this entry.

Defender takeaway (updated): the acute threat has resolved without confirmed compromise; the remaining action is to confirm any Kiteworks deployment, including the Advanced Forms module specifically, runs release 9.5.1 or later.

threat26 Sep 04:04Zmulti-sourceOpen finding ↗