Skip to content

Security1 publisher2 min readPublished

Kiteworks' shutdown all-clear sends self-hosted Advanced Forms customers to support

Kiteworks lifted its shutdown advice on Sunday and sent customers running self-hosted Advanced Forms, enabled at under 50 organisations, to support. The flaw has been described only in private customer emails, so those operators are handling it case by case with the vendor.

The Watch · Security desk

Illustration accompanying Kiteworks' shutdown all-clear sends self-hosted Advanced Forms customers to support

What happened

  • On Friday Kiteworks advised a nine-hour precautionary shutdown of all on-premises and customer-hosted instances, warning that hackers may target zero-days in its products.
  • Customer emails, one copy of which was shared on Reddit, blamed a severe flaw in Advanced Forms and said the DPE, file transfer, MFT and other products are unaffected.
  • Kiteworks says it has no evidence the flaw was exploited and is sharing intelligence about the threat with industry partners including Mandiant.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction The Friday notice warned of zero-days across Kiteworks products while the emails confine the flaw to Advanced Forms, so operators are planning against a scope that exists only in a private message.
  • exposure Self-hosted Advanced Forms operators are the only group whose return to service runs through vendor support, and theirs is the one product the company says the flaw reaches.
  • decision Advanced Forms self-hosters must choose whether to restore service on 9.5.1 before support confirms it, because Balonis's version statement covers known flaws in general, not their product.
  • cost On-prem operators among the more than 99% of customers without Advanced Forms took the shutdown window for a flaw in a product they do not run.

Kiteworks, formerly Accellion, describes the federal warning as a statement of intent [1]. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," CISO Frank Balonis said [9]. He also said: "We have no indication that Kiteworks or our customers' systems have been compromised, so this advisory is preventative rather than a response to a confirmed breach." [10]

The public record does not show active exploitation. The company says it has no evidence the flaw was exploited [8]. The tip named Kiteworks systems as a target [9]. By the company's account, nobody was reported inside them [10]. Balonis refers only to "a threat actor" and "federal intelligence authorities" [9], so the tip cannot yet be tied to a known campaign.

The response was wider than the stated scope. The Friday notice covered every on-premises and customer-hosted instance and warned of zero-day vulnerabilities in the company's products, plural [2]. The customer emails confine the vulnerability to Advanced Forms and list the DPE, file collaboration, file transfer, email encryption, APIs and MFT as unaffected [7]. Those emails put Advanced Forms at fewer than 1% of customers [7]. More than 99% of the customer base does not have the product enabled [1]. Systems Kiteworks hosts on customers' behalf "have been brought back up and are operating normally," the company said [5].

The sourcing splits in two. Kiteworks' public announcement did not detail the threat [6]. The product name, the under-50 count and the list of unaffected products come from emails to customers, and SecurityWeek quoted a copy shared on Reddit [7]. The under-50 figure is the vendor's own count, sent privately.

Sunday's notice lifted the shutdown recommendation for all customers [3] and added one line: "Customers with self-hosted Advanced Forms should contact Customer Support for assistance." [4] On versions, Balonis said: "Kiteworks has accounted for all known vulnerabilities in our current release, 9.5.1, and we continue to recommend customers run the latest version." [11] That statement covers the release as a whole. It does not say the Advanced Forms flaw is fixed in 9.5.1. The support referral suggests those instances are being handled one at a time.

The self-hosted group is some part of the fewer than 50 organisations with Advanced Forms enabled [7]. For them, the evidence supports running this as an open incident until support confirms a fix. The federal tip named Kiteworks systems as the target [9], and Advanced Forms is the one product the company says is vulnerable [7]. For every other customer, the record supports bringing systems back online as Kiteworks advised on Sunday [3].

What to watch

  • A Kiteworks advisory or CVE for Advanced Forms that names the fixed release, which would show whether 9.5.1 closes the flaw.
  • Indicators or attribution from Mandiant or federal authorities, which would let the tip be tied to a known actor or campaign.
  • Any Advanced Forms customer reporting compromise, which would contradict Kiteworks' statement that it has no evidence of exploitation.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories