Progress ShareFile Storage Zones Controller (SZC) auth bypass and RCE chain (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Chained CVE-2026-2699 and CVE-2026-2701 in Progress ShareFile Storage Zones Controller (SZC) can expose internet-facing branch 5.x deployments to unauthenticated file exfiltration and pre-auth RCE. Progress fixed the issues in ShareFile 5.12.4 on March 10. Exposure remains significant because scans found roughly 30,000 public SZC instances, although no active exploitation had been observed at publication.
Related Happenings
Progress ShareFile access disruption during security threat investigation
Service Disruption
H score1
First: 13.07.2026 15:05
Last: 13.07.2026 15:05
Sources 1
About this happening:
Progress ShareFile experienced a customer-access disruption after Progress Software identified a credible external security threat targeting Storage Zone Controllers...
Progress ShareFile access disruption during security threat investigation
Service DisruptionAbout this happening: Progress ShareFile experienced a customer-access disruption after Progress Software identified a credible external security threat targeting Storage Zone Controllers...
Progress ShareFile Storage Zone Controller access disruption
Service Disruption
H score53
First: 10.07.2026 19:30
Last: 10.07.2026 19:30
Sources 1
About this happening:
ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...
Progress ShareFile Storage Zone Controller access disruption
Service DisruptionAbout this happening: ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...
Latest development: 14.07.2026 19:08
Progress confirmed a high-severity zero-day path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller and released versions 5.12.5 and 6.0.2 to patch the flaw. Progress said the update follows the emergency shutdown of affected controllers and that it has no indication of unauthorized access to any ShareFile customer account or data.
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/Mitigation
H score44
First: 10.07.2026 19:26
Last: 10.07.2026 19:26
Sources 1
About this happening:
Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/MitigationAbout this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Latest development: 14.07.2026 19:08
Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.
Timeline
-
02.04.2026 16:33 1 articles · 3mo ago
watchTowr confirms chained Progress ShareFile SZC bypass and RCE
Technical Analysis UpdatewatchTowr confirms the full exploit chain against Progress ShareFile Storage Zones Controller branch 5.x after identifying CVE-2026-2699 and CVE-2026-2701, showing how an authentication bypass can open the admin interface and lead to remote code execution and unauthenticated file exfiltration.
Show sources
- New Progress ShareFile flaws can be chained in pre-auth RCE attacks — www.bleepingcomputer.com — 02.04.2026 16:33
-
02.04.2026 16:33 1 articles · 3mo ago
Progress releases ShareFile 5.12.4 for SZC vulnerabilities
Mitigation Patch UpdateProgress addresses CVE-2026-2699 and CVE-2026-2701 in Progress ShareFile 5.12.4, closing the Storage Zones Controller branch 5.x issues that enable admin access, secret handling abuse, and remote code execution.
Show sources
- New Progress ShareFile flaws can be chained in pre-auth RCE attacks — www.bleepingcomputer.com — 02.04.2026 16:33
-
02.04.2026 16:33 2 articles · 3mo ago
Public disclosure of Progress ShareFile SZC exploit chain and exposed instances
Initial DisclosurePublic disclosure details how CVE-2026-2699 and CVE-2026-2701 can be chained in Progress ShareFile Storage Zones Controller branch 5.x to enable unauthenticated file exfiltration and pre-auth RCE, while noting that ShadowServer Foundation observes 700 internet-exposed Progress ShareFile instances in the United States and Europe and that no active exploitation in the wild has been observed.
Show sources
- New Progress ShareFile flaws can be chained in pre-auth RCE attacks — www.bleepingcomputer.com — 02.04.2026 16:33
- New Progress ShareFile flaws can be chained in pre-auth RCE attacks — www.bleepingcomputer.com — 02.04.2026 16:33