
Kiteworks has warned users of its products to shut down their managed file transfer (MFT) servers immediately after apparently being alerted to the existence of a highly-dangerous zero-day vulnerability.
The company, formerly known as Accellion, bills itself as providing a secure control plane for data exchange. However, thanks to the utility of its core file transfer product in spreading malware and other nasties it has become a serial target for threat actors attempting to compromise multiple downstream users via software supply chain attacks.
At the time of writing, the latest vulnerability to draw attention has not yet been assigned a CVE designation and no information has been made public as to the conditions in which it becomes exploitable.
The shutdown notice – which was first reported by Germany-based outlet Heise, citing an email to customers it received – applies worldwide for a six-hour period on Saturday 26 September, from 3am to 9am in the UK, but the organisation has suggested servers are shut down prior to that.
“We have received credible threat intelligence from law enforcement indicating an attack on Kiteworks systems may be imminent this weekend,” said Frank Balonis, Kiteworks chief information security office (CISO), in the email.
In a further statement, Balonis said he was unaware of any compromise of Kiteworks services, and said the move was being taken “out of an abundance of caution”.
Jake Knott, head of threat intelligence at Watchtowr, a vulnerability management platform provider, confirmed he was actively tracking an emerging threat to Kiteworks appliances.
Knott said that the suggestion a customer shut off their servers was both highly unusual, and a very bad sign.
“There is no known CVE, patch, or additional technical details available - but nobody requests that their entire customer base to unplug production systems over the weekend because of a hunch,” he said.
“Managed File Transfer appliances remain an extremely lucrative and achievable target for attackers of every motivation, allowing for both Initial Access and immediate access to sensitive information that can be used for extortion, or further pivoting,” Knott told Computer Weekly via email.
“Vulnerabilities impacting MFT appliances rarely remain a secret for long, and typically rapidly accelerate from targeted exploitation to indiscriminate, in-the-wild exploitation, with both researchers and attackers likely already throwing the codebase through their favourite LLMs.”
Knott said Kiteworks’ somewhat vague assertions raised multiple questions, particularly given it has asked users to power off systems that do not face the internet. “What is the vulnerability, what specifically does it impact, how is it exploited and has “turn it off and leave it off” officially become a security control?” he mused.
But while he said Kiteworks customers should heed its advice, it was also entirely possible that the publicity around the undisclosed zero-day might push attackers underground for now.
MFT: A target for ransomware
Cleo, Fortra, Progress Software, and Kiteworks ‘ancestor’ Accellion – the list of MFT service suppliers targeted by threat actors is a long one, and the effects can be problematic, if not downright devastating for their customers.
But why are MFT systems such tempting targets? Mostly, it is because they control vast flows of sensitive, often regulated user data in a single location. In practice, this means one single vulnerability can provide a ‘successful’ threat actor with access to vast numbers of organisations. This is powerful leverage for financially-motivated ransomware gangs.
Take car rental firm Hertz, which was targeted by the Cl0p ransomware crew after supposedly being compromised through a vulnerability in Cleo products in April 2025, or cloud data management and security services supplier Rubrik, which was likewise hit following a breach of Fortra’s GoAnywhere product.
But perhaps the most infamous example of an MFT supply chain breach occurred at the end of May 2023, when a vulnerability in Progress Software’s MOVEit tool was mercilessly exploited, with UK-based targets including the BBC, Boots, and British Airways.
The Progress Software breaches were also orchestrated by the Cl0p ransomware gang, which ultimately hit well over a thousand targets via MOVEit. Cl0p makes a point of targeting large numbers of victims simultaneously and its members are particularly partial to MFT flaws for this reason.
While, as of Friday 25 September, there is no public evidence to suggest the involvement of Cl0p in the Kiteworks incident, the crew remains one of the most prolific ransomware gangs operating today, and is also currently involved in a cyber criminal turf war after being targeted by the teenage ShinyHunters crew, which accuses it of ‘stealing’ a vulnerability they found first.