Summary
Kiteworks has issued an emergency advisory urging all on-premises and private cloud customers to shut down their servers for a minimum of six hours following intelligence suggesting active exploitation of a potential unpatched vulnerability. Kiteworks has not disclosed the vulnerability class, assigned a CVE, or specified the attack vector. The advisory instructs customers to take servers offline immediately, contact Kiteworks support, and not bring servers back online until receiving a patch or mitigation directly from Kiteworks.
Timeline
| Date | Event |
|---|---|
| Sep 24, 2026 | Kiteworks receives intelligence suggesting zero-day exploitation; issues emergency 6-hour shutdown advisory |
| Sep 24-25, 2026 | BleepingComputer reports advisory; no CVE assigned; no patch available; TTO-2026-0925-168 published |
What Happened
Kiteworks is an enterprise content collaboration platform for regulated industries including defense contractors, federal agencies, financial institutions, and healthcare systems — organizations whose data attracts nation-state actors and ransomware operators. The platform handles content subject to CMMC, FedRAMP, HIPAA, GDPR, and ITAR requirements.
Kiteworks’ decision to advise preemptive shutdown rather than await a patch indicates the company assessed exploitation risk as immediate and the vulnerability as not mitigatable through configuration changes alone. A six-hour shutdown advisory for enterprise file sharing infrastructure is an unusually aggressive recommendation. Organizations running Kiteworks should follow the advisory immediately regardless of whether they have observed indicators of compromise. TTO will update this bulletin when a CVE is assigned and patch details are available.
Domain Intelligence
kiteworks.com — 60.15
kiteworks.com scores in the low-trust range at 60.15. The T5_NO_CORPUS_HITS flag indicates no topology-layer observations for kiteworks.com in the engine’s corpus prior to this incident — an absence observation, not a negative finding. Kiteworks is the vendor of the affected platform and the party that issued the emergency advisory.
The Trust Observatory · thetrustobservatory.com · September 25, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026