Advisory
Published 2026-09-25
Verified 2026-09-27

Kiteworks (ex-Accellion): LE-intel precautionary 6-hour worldwide shutdown window 26 Sep 02:00–08:00 UTC — not a confirmed breach

Kiteworks CISO Frank Balonis emailed customers 25 September 2026 after receiving credible law-enforcement / federal intelligence that a threat actor may attempt to target some customer Kiteworks systems over the weekend. Vendor recommends a precautionary six-hour shutdown on Saturday 26 September (02:00–08:00 UTC; Heise: Central Europe 04:00–10:00; time-zone list spans AEST to PDT), including systems not Internet-facing, and to take systems offline before the window if possible. Kiteworks told BleepingComputer / TechCrunch / Recorded Future News it is not aware of any compromise of Kiteworks systems; advisory is preventative. Support told Heise the aim is to protect against potential zero-day attacks; Balonis statements do not confirm a CVE or named actor. Known vulns said fixed in current release 9.5.1 — keep current after restart. Kiteworks (formerly Accellion) is widely used for secure file transfer by government, finance and enterprises; Clop historically targeted similar MFT platforms (FTA/MOVEit) — attribution for this weekend window is unconfirmed. Primary wire: Heise (25 Sep); confirmations: BleepingComputer / TechCrunch / Recorded Future News; defender note: Sophos CTU.

Product
Kiteworks secure file-transfer / collaboration appliances and cloud
Versions
Vendor: all known vulnerabilities addressed in current release 9.5.1; shutdown guidance applies regardless of version and network topology (Heise).
Exploited in Australia?
unknown
Patch to
Follow vendor customer email: shut down Kiteworks for the 26 Sep 02:00–08:00 UTC window (or earlier); confirm 9.5.1+ before returning to service; treat as MFT high-value target — review external exposure, admin MFA, and egress; watch vendor channel for post-window guidance

Primary: Heise — Imminent zero-day attack: Kiteworks urges shutdown (25 Sep 2026) · Vendor: Kiteworks (vendor site; customer email / CISO statements via press) · BleepingComputer — Kiteworks 6-hour shutdown (25 Sep 2026); also TechCrunch / Recorded Future News

tech australia cloud