CVE-2026-2699: exploitation status and patch state

CVE-2026-2699 · CVSS 9.8 CRITICAL

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

Is CVE-2026-2699 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-2699

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.