Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security threat. The instruction affects on-premises Windows servers that bridge the cloud service and customer-managed storage. Progress says it has no indication of unauthorized access to ShareFile accounts or data, but it has temporarily disabled access for affected customers while it investigates.
Related Happenings
Progress Software ShareFile Storage Zone Controller path traversal patch release
Security Patch Release
H score38
First: 14.07.2026 19:08
Last: 14.07.2026 19:08
Sources 1
How related:
The company has released versions 5.12.5 and 6.0.2 of the ShareFile Storage Zone Controller and urges all customers to install the security updates as soon as possible.
About this happening:
Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...
Progress Software ShareFile Storage Zone Controller path traversal patch release
Security Patch ReleaseHow related: The company has released versions 5.12.5 and 6.0.2 of the ShareFile Storage Zone Controller and urges all customers to install the security updates as soon as possible.
About this happening: Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...
ShareFile Storage Zone Controller path traversal zero-day path traversal flaw
Vulnerability
H score1
First: 14.07.2026 19:08
Last: 14.07.2026 19:08
Sources 1
How related:
In an update sent to customers today, Progress says its investigation identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller.
About this happening:
Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...
ShareFile Storage Zone Controller path traversal zero-day path traversal flaw
VulnerabilityHow related: In an update sent to customers today, Progress says its investigation identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller.
About this happening: Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...
Progress ShareFile access disruption during security threat investigation
Service Disruption
H score1
First: 13.07.2026 15:05
Last: 13.07.2026 15:05
Sources 1
How related:
Progress said there is no evidence of unauthorized access to ShareFile accounts or data but it confirmed having temporarily disabled access to these accounts.
About this happening:
Progress ShareFile experienced a customer-access disruption after Progress Software identified a credible external security threat targeting Storage Zone Controllers...
Progress ShareFile access disruption during security threat investigation
Service DisruptionHow related: Progress said there is no evidence of unauthorized access to ShareFile accounts or data but it confirmed having temporarily disabled access to these accounts.
About this happening: Progress ShareFile experienced a customer-access disruption after Progress Software identified a credible external security threat targeting Storage Zone Controllers...
Progress ShareFile Storage Zone Controller access disruption
Service Disruption
H score53
First: 10.07.2026 19:30
Last: 10.07.2026 19:30
Sources 1
How related:
The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts.
About this happening:
ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...
Progress ShareFile Storage Zone Controller access disruption
Service DisruptionHow related: The company has temporarily disabled access to the affected accounts, a step it says it took "out of an abundance of caution" while it works with internal and external security experts.
About this happening: ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...
Latest development: 14.07.2026 19:08
Progress confirmed a high-severity zero-day path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller and released versions 5.12.5 and 6.0.2 to patch the flaw. Progress said the update follows the emergency shutdown of affected controllers and that it has no indication of unauthorized access to any ShareFile customer account or data.
Progress Software security patch release for CVE-2026-4670
Security Patch Release
H score44
First: 04.05.2026 19:34
Last: 04.05.2026 19:34
Sources 1
About this happening:
Progress Software has released MOVEit Automation updates to fix CVE-2026-4670 and CVE-2026-5174, including a critical authentication bypass that could expose e...
Progress Software security patch release for CVE-2026-4670
Security Patch ReleaseAbout this happening: Progress Software has released MOVEit Automation updates to fix CVE-2026-4670 and CVE-2026-5174, including a critical authentication bypass that could expose e...
Timeline
-
14.07.2026 19:08 1 articles · 10d ago
Progress releases ShareFile Storage Zone Controller patches for path traversal zero-day
Mitigation Patch UpdateProgress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.
Show sources
- Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown — www.bleepingcomputer.com — 14.07.2026 19:08
-
10.07.2026 19:26 4 articles · 13d ago
Progress tells ShareFile Storage Zone Controller customers to shut down servers
Initial DisclosureProgress Software warned ShareFile customers using Storage Zone Controllers to immediately shut down the Windows servers hosting the on-premises component after identifying a credible external security threat. The company said it had no indication of unauthorized access to any Progress ShareFile accounts or data, temporarily disabled access for affected customers, and said the shutdown step was necessary because cloud-side access restrictions alone were not enough to mitigate the threat.
Show sources
- Progress urges ShareFile customers to shut down servers over "credible" threat — www.bleepingcomputer.com — 10.07.2026 19:26
- Progress urges ShareFile customers to shut down servers over "credible" threat — www.bleepingcomputer.com — 10.07.2026 19:26
- URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat — thehackernews.com — 10.07.2026 19:30
- Progress Software Warns of "External Security Threat" to ShareFile — www.infosecurity-magazine.com — 13.07.2026 15:05