Find notable cyber news and cases, enriched with sources, timelines, and signals.

Progress security patch release for CVE-2026-2699

Security Patch Release
First reported
Last updated
Happening score
H score 68
1 unique sources, 1 articles

Summary

Hide ▲

Progress released ShareFile 5.12.4 on March 10 to fix CVE-2026-2699 and CVE-2026-2701 in the Storage Zones Controller (SZC) for branch 5.x. The update closes an authentication-bypass and RCE chain that could lead to unauthenticated file exfiltration from affected environments. Administrators should move vulnerable systems to the patched build quickly because the exposed component can provide a path to full compromise.

Related Happenings

Progress ShareFile access disruption during security threat investigation

Service Disruption
H score1 First: 13.07.2026 15:05 Last: 13.07.2026 15:05 Sources 1

About this happening: Progress ShareFile experienced a customer-access disruption after Progress Software identified a credible external security threat targeting Storage Zone Controllers...

Progress ShareFile Storage Zone Controller access disruption

Service Disruption
H score53 First: 10.07.2026 19:30 Last: 10.07.2026 19:30 Sources 1

About this happening: ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...

Latest development: 14.07.2026 19:08

Progress confirmed a high-severity zero-day path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller and released versions 5.12.5 and 6.0.2 to patch the flaw. Progress said the update follows the emergency shutdown of affected controllers and that it has no indication of unauthorized access to any ShareFile customer account or data.

Progress ShareFile Storage Zone Controllers shutdown guidance

Advisory/Mitigation
H score44 First: 10.07.2026 19:26 Last: 10.07.2026 19:26 Sources 1

About this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...

Latest development: 14.07.2026 19:08

Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.

Gitea Docker images security update (CVE-2026-20896)

Security Patch Release
H score51 First: 06.07.2026 19:28 Last: 06.07.2026 19:28 Sources 1

About this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...

Progress LoadMaster CVE-2026-8037 patch release

Security Patch Release
H score52 First: 30.06.2026 10:38 Last: 30.06.2026 10:38 Sources 1

About this happening: Progress published fixed LoadMaster versions for CVE-2026-8037, closing a pre-auth root command execution path on appliances with the API enabled. Administrators r...

Timeline

  1. 02.04.2026 03:00 1 articles · 3mo ago

    watchTowr confirms ShareFile SZC exploit chain

    Technical Analysis Update

    watchTowr confirms that CVE-2026-2699 and CVE-2026-2701 can be chained in the Storage Zones Controller (SZC) of Progress ShareFile branch 5.x, where the authentication bypass opens access to admin settings needed to complete the remote code execution path and place malicious ASPX webshells.

    Show sources
  2. 02.04.2026 03:00 2 articles · 3mo ago

    Progress releases ShareFile 5.12.4

    Mitigation Patch Update

    Progress releases ShareFile 5.12.4 for branch 5.x Storage Zones Controller (SZC) after responsible disclosure, addressing CVE-2026-2699 and CVE-2026-2701 and removing the vulnerable build that could be chained for unauthenticated file exfiltration and pre-auth RCE.

    Show sources
  3. 02.04.2026 03:00 1 articles · 3mo ago

    watchTowr publicly details the ShareFile vulnerability chain

    Initial Disclosure

    watchTowr publicly details how CVE-2026-2699 and CVE-2026-2701 can be chained in Progress ShareFile to enable unauthenticated file exfiltration and pre-auth RCE, while noting about 30,000 Storage Zone Controller instances exposed on the public internet, 700 internet-exposed Progress ShareFile instances observed by ShadowServer Foundation, and no active exploitation in the wild as of writing.

    Show sources