Vulnerabilities · 63 days ago
A vendor asking customers to take the service offline changes the problem from patching to continuity and possible compromise. The standard response — wait for a CVE and apply a fix — is too slow when the management tier itself may be the exposure point.
Progress told ShareFile customers to shut down Windows servers running Storage Zone Controllers because of a credible external security threat. It also temporarily disabled access to affected accounts, and said it has no indications of unauthorized access to ShareFile accounts or data while it investigates with internal and external security experts.
For teams that run file-sharing gateways, shutdown notices are not routine maintenance signals. They can mean the control plane is under enough suspicion that the vendor wants it isolated before the flaw is fully named.
CVEs in this update
50 CVEs
Across Windows Server, Windows 10, Windows 11, and related packages.
16 critical · 18 high · 5 medium · 0 low
1 in CISA KEV · 7 with EPSS above 1%
Highest severity: CVE-2026-50746 · 10.0 CRITICAL
Highest EPSS: CVE-2025-5777 · 100%
Showing the top 10 by KEV, EPSS, and severity.
1 source covering this story
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
From a rushed ShareFile shutdown to poisoned npm packages and AI assistants tricked into installing malware, here's every threat you need to know this
Part of the PlainSec briefing for 2026-07-13