KiteWorks Ordered a Global Power-Off — And There Is Nothing to Patch
A file-transfer vendor that cannot scope its own zero-day chose the last control left: unplug everything. That instruction, not a CVE, is the story — and it lands on the systems holding your most regulated data.
The detail that should stop you is what the instruction covers. KiteWorks CISO Frank Balonis told customers to power off all systems, including those not reachable from the internet. A vendor only does that when it cannot bound the flaw by version, network position, or compensating control — or will not risk trying. Moses Frost's read carries weight here: a warning tied to a specific date implies an exploit simple enough to fire at scale, a profile he last saw with Drupalgeddon. As of publication there is no CVE, no IOC, no patch, and no named actor.
Why this category, and why the blast radius is regulatory
Secure file-exchange platforms hold precisely the data regulators care about, which is why the category has a documented mass-extortion history — MOVEit and Accellion FTA, the legacy product of the company that later rebranded as Kiteworks. The current platform is a different product, but attackers would run the same data-theft-and-extortion play. Assume any compromise becomes a HIPAA, GDPR, or contractual notification event for every counterparty whose files traversed your instance. This is the concrete case behind Adrian Sanabria's "IT asbestos" label: products exposed to the internet by design, built on decades-old codebases, and dangerous even when fully patched.
The rest of the queue
KiteWorks is not the only fire. Seven CVSS 9+ flaws landed in CISA KEV on three-day deadlines, and reading the list by function rather than vendor reveals the pattern all three sources independently flag — attackers are hitting the systems that tell the rest of your network what to trust:
- F5 BIG-IP APM (CVE-2026-94127) — heap overflow to unauthenticated RCE on an OAuth Authorization Server; F5 confirms it is a data-plane issue, so management-interface lockdown does nothing, and Appliance-mode hardening puts your most locked-down boxes in scope. The federal KEV deadline lapsed September 25.
- Check Point Security Management (CVE-2026-93616, CVE-2026-85102) — the server that pushes policy to every gateway; one is a zero-day under active attack.
- Arista VeloCloud Orchestrator (CVE-2026-93952), WSO2 (CVE-2026-5430, CVSS 10.0), Adobe Commerce/Magento (CVE-2026-71362), and Zyxel GS1900 (CVE-2026-7273).
Separately, JetBrains TeamCity CVE-2026-63077 — in KEV since August 5 — is confirmed ransomware-used. Ed Skoudis's reminder applies to the whole list: "unknown" in KEV's ransomware field means unknown, not no.
Any edge appliance, identity server, or file-transfer box you cannot patch — or deliberately unplug — within 72 hours is a standing breach risk.
The Hacker News adds a pre-auth SQLi in Roundcube (CVE-2026-48842, CVSS 8.1) exploited on the same day the WSO2 and Magento entries hit KEV. Three confirmed-exploited flaws in a single day, on top of an unscoped power-off, is what the collapsed exploitation clock looks like in practice.
What to do
Power off every KiteWorks node — internet-facing and internal — before 02:00 UTC Saturday, keep them down until 08:00 UTC, and run 72 hours of heightened egress and admin-session detection after restart.
Map the seven KEV additions plus TeamCity CVE-2026-63077 to asset inventory and remediate internet-facing instances inside the three-day KEV SLA, starting with Check Point Management Server and the F5 APM OAuth profile.
Open a compromise assessment — not a patch ticket — on any TeamCity server that was internet-reachable and unpatched since August 5, now that CVE-2026-63077 is confirmed ransomware-used.