supply-chaintrade-pressNewsThe Broadside1 min read

Kiteworks tells customers to shut down Saturday over zero-day threat

Federal intelligence flagged a credible threat, but Kiteworks hasn't confirmed a CVE, a patch, or an attacker, leaving practitioners with a shutdown window and a lot of unanswered questions.


TL;DR

Kiteworks emailed customers this week recommending they shut down the company's managed file transfer platform during a six-hour window on Saturday. CISO Frank Balonis told Recorded Future News the company received "credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems." Balonis said the advisory is preventative ("we are not aware of any compromise") and that all known vulnerabilities are addressed in the current 9.5.1 release. A Kiteworks customer-support official separately told German outlet Heise the warning involved a potential zero-day, but the company declined to say whether a CVE had been assigned or which group was involved. Neither the FBI nor CISA commented.

The timing is what makes this one land differently. Kiteworks is a managed file transfer vendor, the same product category as the Accellion FTA appliance that Clop exploited via zero-day in December 2020, ultimately hitting the University of Colorado, Flagstar Bank, Bombardier, Kroger, and dozens of others. Kiteworks is, in fact, the same company under a new name. So when the current CISO sends a Saturday-shutdown email citing federal intelligence, the history isn't background color. It's part of the threat model.

Jake Knott of watchTowr put it plainly: "There is no known CVE, patch, or additional technical details available, but nobody requests that their entire customer base unplug production systems over the weekend because of a hunch."

Kiteworks told Recorded Future News that "all known vulnerabilities are addressed in our current release, 9.5.1." But the company wouldn't say whether the intelligence they received points to something that isn't known yet, which is the definition of a zero-day. The support official's comment to Heise is the only on-record use of that term.

The NVD shows a cluster of Kiteworks vulnerabilities addressed across versions 9.2.0 through 9.3.0 this year, SQL injection, IDOR, SSRF bypass, OS command injection, and credential-transport issues among them [https://nvd.nist.gov/vuln/detail/CVE-2026-24782] [https://nvd.nist.gov/vuln/detail/CVE-2026-23638] [https://nvd.nist.gov/vuln/detail/CVE-2026-28269]. None of those appear connected to Saturday's shutdown, they're disclosed, rated, and patched. What's unsettling is the gap between "all known vulnerabilities are addressed" and "please turn everything off anyway."

For the practitioner, the immediate move is the shutdown if you haven't already executed it. After that, watch for whether a CVE drops, and whether a patch lands before Monday. The last time a Clop zero-day hit this product category, the window between exploitation and public disclosure was measured in weeks, not days.


Published ·Deep Fathom