Progress ShareFile access disruption during security threat investigation
Service Disruption
Summary
Hide ▲
Show ▼
Progress ShareFile experienced a customer-access disruption after Progress Software identified a credible external security threat targeting Storage Zone Controllers. The company temporarily disabled access for affected accounts and told customers to shut down the hosting server while it investigated, creating an immediate availability and operational impact for enterprise file-sharing users.
Related Happenings
ShareFile Storage Zone Controller path traversal zero-day path traversal flaw
Vulnerability
H score1
First: 14.07.2026 19:08
Last: 14.07.2026 19:08
Sources 1
About this happening:
Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...
ShareFile Storage Zone Controller path traversal zero-day path traversal flaw
VulnerabilityAbout this happening: Progress confirmed a high-severity path traversal zero-day in ShareFile Storage Zone Controller, exposing all 5.x and 6.x versions to arbitrary file read and write ris...
Progress Software ShareFile Storage Zone Controller path traversal patch release
Security Patch Release
H score38
First: 14.07.2026 19:08
Last: 14.07.2026 19:08
Sources 1
About this happening:
Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...
Progress Software ShareFile Storage Zone Controller path traversal patch release
Security Patch ReleaseAbout this happening: Progress Software released 5.12.5 and 6.0.2 for ShareFile Storage Zone Controller after a high-severity zero-day path traversal vulnerability forced last week’s sh...
Progress ShareFile Storage Zone Controller access disruption
Service Disruption
H score53
First: 10.07.2026 19:30
Last: 10.07.2026 19:30
Sources 1
About this happening:
ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...
Progress ShareFile Storage Zone Controller access disruption
Service DisruptionAbout this happening: ShareFile Storage Zone Controller customers lost access when Progress Software temporarily disabled affected accounts and marked them not operational while investigati...
Latest development: 14.07.2026 19:08
Progress confirmed a high-severity zero-day path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller and released versions 5.12.5 and 6.0.2 to patch the flaw. Progress said the update follows the emergency shutdown of affected controllers and that it has no indication of unauthorized access to any ShareFile customer account or data.
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/Mitigation
H score44
First: 10.07.2026 19:26
Last: 10.07.2026 19:26
Sources 1
How related:
Users are also urged to manually shut down the server hosting their Storage Zone Controller.
About this happening:
Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Progress ShareFile Storage Zone Controllers shutdown guidance
Advisory/MitigationHow related: Users are also urged to manually shut down the server hosting their Storage Zone Controller.
About this happening: Progress Software has told ShareFile customers using Storage Zone Controllers to shut down their servers immediately after detecting a credible external security...
Latest development: 14.07.2026 19:08
Progress Software identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller, reserved a CVE identifier for it, and released versions 5.12.5 and 6.0.2 to patch the flaw and restore the controllers after updating. The company said it has no indication of unauthorized access to any ShareFile customer account or data and no active threat has been identified.
Progress ShareFile Storage Zones Controller (SZC) auth bypass and RCE chain (multiple vulnerabilities)
Vulnerability
H score60
First: 02.04.2026 16:33
Last: 02.04.2026 16:33
Sources 1
About this happening:
Chained CVE-2026-2699 and CVE-2026-2701 in Progress ShareFile Storage Zones Controller (SZC) can expose internet-facing branch 5.x deployments to unauthenticated...
Progress ShareFile Storage Zones Controller (SZC) auth bypass and RCE chain (multiple vulnerabilities)
VulnerabilityAbout this happening: Chained CVE-2026-2699 and CVE-2026-2701 in Progress ShareFile Storage Zones Controller (SZC) can expose internet-facing branch 5.x deployments to unauthenticated...
Timeline
-
13.07.2026 03:00 2 articles · 14d ago
Progress Software restores ShareFile cloud access while keeping Storage Zone Controllers offline
Victim Impact UpdateProgress Software restores ShareFile cloud access for customers with Storage Zone Controllers, but tells them the controllers must remain turned off while the investigation continues and says it has no evidence of unauthorized access to customer accounts or data.
Show sources
- Progress Software Warns of "External Security Threat" to ShareFile — www.infosecurity-magazine.com — 13.07.2026 15:05
- Progress Software Warns of "External Security Threat" to ShareFile — www.infosecurity-magazine.com — 13.07.2026 15:05
-
10.07.2026 03:00 1 articles · 17d ago
Progress Software warns ShareFile customers of credible external security threat
Initial DisclosureProgress Software notifies some ShareFile customers of a credible external security threat targeting Storage Zone Controllers and temporarily disables access to affected accounts while it assesses the issue.
Show sources
- Progress Software Warns of "External Security Threat" to ShareFile — www.infosecurity-magazine.com — 13.07.2026 15:05
-
10.07.2026 03:00 1 articles · 17d ago
Progress Software tells ShareFile customers to shut down Storage Zone Controller servers
Mitigation Patch UpdateProgress Software tells ShareFile customers to manually shut down the server hosting their Storage Zone Controller and says it has launched internal and external security investigations while the threat is assessed.
Show sources
- Progress Software Warns of "External Security Threat" to ShareFile — www.infosecurity-magazine.com — 13.07.2026 15:05