Kiteworks Told Customers to Go Dark for Nine Hours After a Federal Warning

Fewer than 50 organisations use the affected feature. No breach has been confirmed. But the feds thought the risk serious enough to pick up the phone.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
A close-up, 16:9 framing, photoreal news-editorial photograph of a modern server rack in a dimly lit data centre, power indicator lights glowing amber and red,
Share

Key points

  • Kiteworks, a secure file-sharing company, told customers to shut down their servers on Friday after US federal intelligence authorities warned of a credible threat targeting its systems.
  • The vulnerability sits inside Advanced Forms, one specific product feature used by fewer than 50 organisations, less than 1% of Kiteworks customers.
  • Kiteworks says it found no evidence of exploitation and lifted the shutdown recommendation by Sunday.
  • A related Microsoft SharePoint flaw, CVE-2026-65660, is confirmed exploited in the wild and carries a federal patch deadline of 28 September 2026.
  • Kiteworks recommends all customers run version 9.5.1, which it says accounts for all known vulnerabilities.

Kiteworks, a company that sells software for moving sensitive files securely between organisations, spent the weekend telling customers to pull the plug on their own servers. US federal intelligence authorities passed the company what it described as credible threat intelligence pointing to possible attacks on its systems.

The shutdown window lasted roughly nine hours. By Sunday, all systems Kiteworks manages on behalf of customers were back online, and self-hosted customers could restart their servers. Customers running a feature called Advanced Forms, a secure data-collection tool, were told to call Kiteworks support before bringing anything back up.

What exactly was the threat?

The risk is a severe vulnerability inside Advanced Forms. Kiteworks hasn't published a CVE identifier or technical breakdown, but its CISO Frank Balonis told customers in a written statement: "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems." He added that the company had no indication any customer system was compromised.

The exposure is narrow. Advanced Forms is active for fewer than 50 organisations worldwide. Every other Kiteworks product, including its file collaboration, email encryption, managed file transfer and API tools, is listed as unaffected.

Kiteworks brought in Mandiant, a well-known incident-response firm, to help assess the threat before any breach was confirmed. That's unusual, and it suggests the federal tip carried genuine weight. We first reported on Kiteworks in August, including its acquisition of Bonfy.AI on 17 September, a deal framed around controlling sensitive data as AI systems move it around. A company investing in that kind of capability doesn't pull the emergency brake lightly.

Why does the SharePoint flaw matter here?

A separate but related story broke the same week. Microsoft SharePoint, the document-sharing platform built into many corporate networks, contains a code injection vulnerability, meaning a flaw that lets an attacker run their own software commands inside a victim's system, tracked as CVE-2026-65660. The US Cybersecurity and Infrastructure Security Agency, CISA, added it to its Known Exploited Vulnerabilities catalogue on 25 September 2026, confirming active use in real attacks.

As we reported on 22 September, what Microsoft initially called a spoofing bug turned out to let logged-in users execute code on the server. The federal patch deadline for CVE-2026-65660 is 28 September 2026. An attacker needs a valid account to exploit it, but that bar isn't high where credentials are routinely phished.

Detail Value
CVE ID CVE-2026-65660
Affected product Microsoft SharePoint
Published 11 August 2026
CISA KEV added 25 September 2026
Federal patch deadline 28 September 2026

The two incidents aren't the same attack. They do, however, point at the same pattern: file-sharing and collaboration tools are a priority target right now, precisely because they sit between organisations and hold sensitive documents.

What should affected users do?

If your organisation uses Kiteworks, confirm you're running version 9.5.1. Users of Advanced Forms specifically should contact Kiteworks support before restarting any self-managed server.

For Microsoft SharePoint on-premises, the patch for CVE-2026-65660 needs to go in immediately. US federal agencies face a hard deadline of 28 September 2026. Watch for unexpected login alerts or unusual file-access activity in SharePoint audit logs in the meantime.

© 2026 Threat Vectr