News / Cybersecurity
Kiteworks Imposes Nine-Hour Outage Due to Critical Flaw in Advanced Forms Published on 28 September 2026 by Christ-loisele (2 min read)
Kiteworks ordered its clients to take their servers offline for nine hours due to a severe vulnerability in its Advanced Forms product. No exploitation has been detected, but the preventive measure aimed to anticipate a potential threat based on information from federal authorities.
A Vulnerability Targeting a Minority Product
The flaw identified by Kiteworks concerns exclusively its Advanced Forms product, used by less than 1% of its clients, or fewer than 50 organizations worldwide, according to the publisher’s statements. This geographical and functional limitation reduces the potential impact, but the severity of the threat justified an exceptional measure: a nine-hour service interruption for on-premises instances and those hosted by clients. Kiteworks clarified that its other products, including file transfer solutions, email encryption, APIs, and MFT platforms, are not affected.
The measure was preventive, based on credible threat intelligence rather than a confirmed attack
Illustration: Lawing Tech
A Preventive Decision Based on Federal Alerts
The recommendation to take systems offline was not triggered by a confirmed attack, but by credible threat information shared by federal intelligence authorities, as confirmed by Frank Balonis, Kiteworks’ Chief Information Security Officer (CISO). In an email shared on Reddit, the company emphasized that this measure was preventive and not a response to a confirmed breach. No evidence of exploitation of the vulnerability has been observed, either at Kiteworks or among its clients. The alert was lifted the following Sunday after the initial announcement, allowing systems to resume normal operation.
Collaboration with Mandiant and Software Update
To enhance transparency and responsiveness, Kiteworks is collaborating with Mandiant , a leading cybersecurity firm, to share information about this threat. The company also stated that version 9.5.1 of Advanced Forms includes all known vulnerabilities , suggesting a rapid fix following the risk identification. Clients using an earlier version or self-hosting Advanced Forms were advised to contact technical support for tailored assistance.
What This Means Here
For businesses and government agencies in Benin and West Africa using solutions similar to Advanced Forms for secure data collection, this incident underscores the importance of actively monitoring cybersecurity alerts , even in the absence of exploitation evidence. A vulnerability targeting a minority product can become an attack vector if exploited by malicious actors, hence the need to regularly update software and rely on partnerships with experts like Mandiant to assess risks. Organizations hosting their infrastructure locally should also anticipate emergency procedures , such as temporary offline measures, in the event of a critical alert.
Sources