CVE-2026-2699
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
Vulnerabilities & Exploits · Zero-Day Exploit
Progress has moved this from a cloud outage to a customer-owned containment problem. The vendor can cut off ShareFile access from its side, but the risky Storage Zone Controllers sit in customer environments, so the attack surface can stay live until those servers are actually shut down.
Progress said it disabled access to ShareFile accounts using Storage Zone Controllers and then started restoring cloud access on day 3, while telling customers to keep the controllers turned off. It said it has no evidence of unauthorized access to ShareFile accounts or data. The relevant exposure sits in the customer-managed Storage Zone Controller layer, not just in the SaaS account layer.
That means hybrid SaaS setups with customer-managed connectors or gateways can leave the hard containment step with the customer even after the vendor service comes back. In this case, patching or restoring the cloud side does not by itself retire the exposed edge device.
5 sources · Jul 14
CVSS 9.8 CRITICAL: customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages.
CVSS 9.1 CRITICAL: authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
BleepingComputer
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw.
originalInfosecurity Magazine
Progress Software Warns of “External Security Threat” to ShareFile
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller
originalHelp Net Security
Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers - Help Net Security
ShareFile security threat prompts Progress Software to disable access to Storage Zone Controllers and urge customers to shut down servers.
originalPart of the PlainSec briefing for 2026-07-10
Every edition of this story: ShareFile Cloud Returns, But Customer Controllers Stay Offline