Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Дата публикации: 29-09-2026 14:13:20

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown.
"During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company

Основное содержимое страницы с новостью.

Ravie LakshmananSep 29, 2026Vulnerability / Enterprise Security

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown.

"During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company said in a statement. "Kiteworks developed and deployed a fix during the window, [and] applied an additional protective layer across all environments."

There is no evidence that the vulnerability has ever been exploited in a malicious context. Other Kiteworks products are not affected by the flaw.

The development comes days after Kiteworks, previously Accellion, urged customers to take their systems offline for a period of nine hours, in addition to shutting down environments it hosts on behalf of customers, after receiving intelligence about a potential imminent cyber attack.

The company stressed that the action was more preventative than a reaction to a confirmed breach of its systems. On September 27, 2026, the shutdown recommendation was lifted.

Kiteworks has not disclosed any specifics about the nature of the flaw, and how it could be exploited. It does not have a Common Vulnerabilities and Exposures (CVE) identifier as of writing. The Hacker News has contacted the company if it plans to release a public advisory about the flaw and assign it a CVE ID for easier tracking.

"Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them," Kiteworks CISO Frank Balonis said.

"We made it anyway, because when the choice is between certainty and convenience, customer data is not something we are willing to gamble with. That decision is what made the rest possible. We would make the same call again tomorrow to protect our customers' data."

Now that the threat window has passed and no anomalies were observed, customers are recommended to bring their Kiteworks system back online.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack05.926-09-2026
2Expecting cyber attack, Kiteworks tells users to turn off servers01025-09-2026
3Server am Samstagmorgen herunterfahren: Kiteworks warnt Admins vor Zero-Day013.4525-09-2026
4Server am Samstagmorgen herunterfahren: Kiteworks warnt Admins vor Zero-Day013.4525-09-2026
5Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation09.2627-09-2026
6Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data04.6225-09-2026
7Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT07.930-09-2026
8Positive Technologies помогла исправить 17 уязвимостей в популярной российской SCADA-системе025.8901-10-2026
9Positive Technologies помогла исправить 17 уязвимостей в популярной российской SCADA-системе025.8901-10-2026
10Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers011.4825-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.31. Источник: thehackernews.com.