TTO-2026-0925-168 · September 25, 2026 Zero-DayCritical

Kiteworks Urges Customers to Shut Down Servers for Six Hours Over Potential Unpatched Zero-Day Attack

kiteworks.comPotential zero-day — no CVE assigned6-hour shutdown advisoryEnterprise file sharing — government / finance / healthcareNo patch at publicationT5_NO_CORPUS_HITS

Summary

Kiteworks has issued an emergency advisory urging all on-premises and private cloud customers to shut down their servers for a minimum of six hours following intelligence suggesting active exploitation of a potential unpatched vulnerability. Kiteworks has not disclosed the vulnerability class, assigned a CVE, or specified the attack vector. The advisory instructs customers to take servers offline immediately, contact Kiteworks support, and not bring servers back online until receiving a patch or mitigation directly from Kiteworks.

Timeline

DateEvent
Sep 24, 2026Kiteworks receives intelligence suggesting zero-day exploitation; issues emergency 6-hour shutdown advisory
Sep 24-25, 2026BleepingComputer reports advisory; no CVE assigned; no patch available; TTO-2026-0925-168 published

What Happened

Kiteworks is an enterprise content collaboration platform for regulated industries including defense contractors, federal agencies, financial institutions, and healthcare systems — organizations whose data attracts nation-state actors and ransomware operators. The platform handles content subject to CMMC, FedRAMP, HIPAA, GDPR, and ITAR requirements.

Kiteworks’ decision to advise preemptive shutdown rather than await a patch indicates the company assessed exploitation risk as immediate and the vulnerability as not mitigatable through configuration changes alone. A six-hour shutdown advisory for enterprise file sharing infrastructure is an unusually aggressive recommendation. Organizations running Kiteworks should follow the advisory immediately regardless of whether they have observed indicators of compromise. TTO will update this bulletin when a CVE is assigned and patch details are available.

Domain Intelligence

kiteworks.com — 60.15

kiteworks.com scores in the low-trust range at 60.15. The T5_NO_CORPUS_HITS flag indicates no topology-layer observations for kiteworks.com in the engine’s corpus prior to this incident — an absence observation, not a negative finding. Kiteworks is the vendor of the affected platform and the party that issued the emergency advisory.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026