#StorageZoneController
Progress Software confirmed a high-severity ShareFile zero-day path traversal flaw behind the Storage Zone shutdown. Patches are released, and no customer account compromise or active threat has been identified. #ProgressSoftware #ShareFile
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software confirmed that a high-severity zero-day path traversal vulnerability forced the emergency shutdown of ShareFile Storage Zone Controllers and has now released patches. The company says there is no indication of customer account compromise or active threat, and urges users to install the updates immediately. #ProgressSoftware #ShareFile #StorageZoneController
www.hendryadrian.com
July 14, 2026 at 7:00 PM
Two chained vulnerabilities (CVE-2026-2699 & CVE-2026-2701) in Progress ShareFile Storage Zones Controller enable unauthenticated file access and remote code execution. Patch version 5.12.4 fixes the issues. #ShareFile #RemoteCodeExec #USA
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile's Storage Zones Controller can be chained to enable unauthenticated file exfiltration and remote code execution on affected systems. The flaws (CVE-2026-2699 and CVE-2026-2701) were reported by watchTowr and fixed in Progress ShareFile 5.12.4 on March 10, but exposed instances should be patched immediately. #ProgressShareFile #StorageZoneController
www.hendryadrian.com
April 2, 2026 at 6:00 PM