Updated: Kiteworks Fixes Critical Advanced Forms Vulnerability; Hosted Environments Operating Normally

During a precautionary shutdown, Kiteworks identified and fixed a critical vulnerability limited to Advanced Forms. The company says hosted environments are operating normally and has no indication of exploitation.

Updated: Kiteworks has now confirmed that it deployed a fix for the critical vulnerability and an additional layer of protection across all environments during the precautionary shutdown.

Kiteworks confirmed that it identified and fixed a critical vulnerability in the Kiteworks Advanced Forms capability during a precautionary shutdown. According to a September 28 announcement, all customers can now resume normal operations, and the company’s hosted environments are operating normally.

The company originally recommended the shutdown based on information about a possible imminent attack. During this period, Kiteworks says it discovered a previously unknown critical vulnerability in a capability enabled for fewer than 1% of customers. The company created and deployed a fix while also adding an additional layer of protection across all environments.

Kiteworks Advanced Forms Remains an Exception for Standalone Deployments

According to information from CyberScoop, the affected capability is Advanced Forms. Kiteworks previously said that customers operating this component separately should contact the vendor’s support team. For these deployments, the company has not publicly disclosed a specific fixed version or exact update procedure.

For administrators, the new information is significant mainly because this is not merely the cancellation of the shutdown recommendation. The vendor has now also confirmed the deployment of a fix for the critical vulnerability and an additional layer of protection. Hosted environments have been restored, according to its statement, but Advanced Forms operated separately must be addressed through Kiteworks support.

Vendor Reports No Signs of Compromise

Kiteworks says it has no indication of compromise of its systems or customer systems. It also has no indication that the vulnerability was exploited. This statement comes from the vendor; independently confirmed information about any potential exploitation is not publicly available at this time.

The company has not disclosed a technical description of the vulnerability, a CVE identifier, indicators of compromise, or the affected software versions. Customers therefore have no public information they could use to independently verify the scope of the fix or search for signs of a possible attack in their own systems.

It has also not been publicly confirmed which actor was reportedly targeting the system according to earlier media reports, or which federal authorities provided the original warning. Kiteworks has not disclosed these details.

What to Watch Next

For customers with standalone Advanced Forms deployments, the current step is to contact the vendor’s support team. Further information could come from a public security advisory containing a CVE, a technical description of the vulnerability, a list of affected versions, and an exact update procedure.

Any instructions or a separate fix for self-hosted deployments will also be important, as will any change in the positions of Kiteworks or the relevant authorities regarding possible exploitation or compromise.

Sources

Verified and updated: 09/30/2026 06:29

Sharing