Kiteworks Patches Critical Flaw, Lifts Shutdown Order
Kiteworks patched the flaw behind its September 26 emergency shutdown advisory. Apply the update before restoring any Kiteworks instance to service.

Kiteworks has patched the critical vulnerability behind its September 26 emergency shutdown advisory and lifted the precautionary guidance telling customers to take servers offline. BleepingComputer reported the update Tuesday morning.
Apply the patch before restoring your Kiteworks instance to service. That’s the action item.
Kiteworks has not published a CVE ID or described the vulnerability class. A formal security advisory may follow, but the patch is available now and that’s what matters.
Background: On September 25, Kiteworks sent an emergency notification to customers telling them to take servers offline for a six-hour window on Saturday, September 26. The company cited threat intelligence about possible active zero-day exploitation but did not disclose the vulnerability, the threat actor, or details of the intelligence. The situation and what it means for MFT platform risk were covered here at the time.
Vendors do not issue emergency mass-shutdown requests unless the intelligence is credible. Emergency guidance that costs customers operational time gets issued when the alternative is worse.
Managed file transfer platforms pull targeted attacks because they handle regulated data from many organizations on a single server. A compromised MFT installation can yield files from dozens of clients at once, which is why Clop ran its 2023 MOVEit campaign through the MFT category rather than targeting individual orgs. The GoAnywhere attacks followed the same pattern. Kiteworks sits in that same risk category, serving customers across healthcare, legal, financial services, and government.
With the patch applied, also restrict external access to Kiteworks management interfaces at the network perimeter as a defense-in-depth control. Watch the Kiteworks security advisories page and the CISA Known Exploited Vulnerabilities catalog for a formal CVE assignment or any KEV addition if exploitation is confirmed.
Related: Kiteworks Flags Potential Zero-Day, Urges Server Shutdown, Clop Moves Leak Site After Grav CMS Attack Confirmed.
Found this useful? Share it.


