Kiteworks Patches Critical Vulnerability, Lifts Precautionary Advisory for Thousands of Global Customers
In a move that highlights the ongoing cat-and-mouse game between cybersecurity vendors and attackers, Kiteworks has lifted its precautionary advisory urging customers to shut down their systems after patching a critical vulnerability. The company, which operates a Private Content Network (PCN) used by thousands of global corporations and government agencies, had issued the warning on Saturday following intelligence from federal authorities about a potentially imminent cyberattack.
For those unfamiliar with Kiteworks’ PCN, it’s a secure file-sharing platform that integrates various services such as email, file sharing, Managed File Transfer (MFT), APIs, and web forms into a single platform. With over 100 million end-users worldwide, the company’s customers include some of the world’s most prominent organizations.
After patching the vulnerability, which was found in an unnamed feature used by less than 1% of its customers, Kiteworks conducted continuous monitoring throughout the period and reported no abnormal activity or indication that any system had been compromised. This means that customers can now bring their systems back online without fear of being targeted by attackers.
However, it’s worth noting that the company has not yet shared additional details on the fixed vulnerability, nor has it assigned a CVE (Common Vulnerabilities and Exposures) ID for tracking purposes. Threat watchdog Shadowserver estimates that nearly 400 Kiteworks instances are accessible over the internet, with most of them located in the United States.
The patching of this critical vulnerability is particularly noteworthy given the company’s history with data breaches. In 2021, cybercrime gang Clop exploited a zero-day attack on Accellion’s File Transfer Appliance (FTA) software, resulting in data breaches impacting several high-profile entities, including cybersecurity firm Qualys and energy giant Shell.
This incident serves as a stark reminder of the importance of staying vigilant and proactive in addressing vulnerabilities. As we move forward, it’s essential for organizations to prioritize security measures, such as implementing robust monitoring tools and keeping software up-to-date, to mitigate the risk of data breaches.
For those who use Kiteworks’ services, this incident is an opportunity to review their own security posture and take steps to ensure that their systems are protected from potential threats. As the cybersecurity landscape continues to evolve, it’s crucial for organizations to stay informed and adapt to emerging risks and vulnerabilities.
Source: Bleeping Computer — 2026-09-29