The Exploit Bulletin

Archives
Log in
Subscribe
September 30, 2026

The Exploit Bulletin — Wednesday, September 30, 2026: 1 issue requires action

Wednesday, September 30, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: Kiteworks Private Content Network


1. Critical flaw in Advanced Forms patched after vendor-ordered emergency shutdown, no CVE yet (Kiteworks)

UNVERIFIED PUBLIC REPORT · NO CVE · DATA EXPOSURE · CRITICAL

The vendor lifted its shutdown order on 2026-09-27 and the fix is now available; self-hosted Advanced Forms customers must actively contact support to get it, and Kiteworks/Accellion file-transfer products have a history of being targeted by data-extortion crews such as Clop once a flaw becomes known.

Kiteworks, the enterprise file-sharing and managed-file-transfer vendor formerly known as Accellion, asked all customers worldwide on Saturday 2026-09-26 to shut down their servers after receiving a warning from federal intelligence authorities of a potentially imminent cyberattack. During the shutdown window it identified and fixed a critical vulnerability in its Advanced Forms secure data collection feature, applied an additional protective layer across all environments, and lifted the shutdown recommendation on 2026-09-27. Kiteworks says the feature is used by under 1% of customers, that all other Kiteworks products are unaffected, and that it has no indication the flaw was ever exploited. No CVE has been assigned, no technical details, attack vector or affected versions have been published, and the vendor has not said what an attacker could do — given the nature of a file-transfer platform and the shutdown order, we treat it as a remotely reachable flaw with data-theft potential until the vendor says otherwise. Shadowserver counts roughly 400 Kiteworks instances exposed to the internet, 234 in the United States.

Affected: not stated — the report concerns the Kiteworks Advanced Forms feature (used by under 1% of customers); hosted instances were fixed by the vendor, self-hosted Advanced Forms deployments are told to contact Kiteworks support; other Kiteworks products are stated to be unaffected

How to Test: Check whether your Kiteworks deployment has the Advanced Forms feature licensed or enabled (Admin console → Applications/Forms); if it is, you are in the affected population. Self-hosted operators should confirm with Kiteworks support whether the fix has been applied to their build. Review web and application logs for the shutdown window (2026-09-26 onward) and for unusual requests to form/data-collection endpoints; the vendor has published no specific indicators of compromise.

How to Patch: Self-hosted Kiteworks with Advanced Forms: contact Kiteworks support to obtain and apply the fix, and disable Advanced Forms or restrict web access to trusted networks until it is applied. Hosted customers: confirm with Kiteworks that the fix and protective layer are in place. Everyone: watch for a forthcoming CVE and release notes from Kiteworks.

Evidence: BleepingComputer: Kiteworks lifts shutdown warning after patching critical flaw · SecurityWeek: Kiteworks urges server shutdown, finds Advanced Forms vulnerability · The Hacker News: Kiteworks fixes critical flaw found during nine-hour precautionary shutdown · TechCrunch: Kiteworks urges customers to shut down servers amid imminent threat

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Thursday, October 1, 2026: 3 issues require action Older → The Exploit Bulletin — Tuesday, September 29, 2026: 1 issue requires action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.