CVE-2026-2701: RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)
Published Apr 2, 2026
·Updated
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
Affected Software
2 affected components
Progress ShareFile Storage Zones Controller (SZC)
Progress ShareFile Storage Zones Controller>=5.0.0<5.12.4
Event History
Apr 2, 2026
CVE Published
via MITRE·01:04 PM
Data Sourced
via MITRE·01:04 PM
DescriptionSeverityWeakness
News Published
via BleepingComputer·01:33 PM
News Published
via BleepingComputer·01:35 PM
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2701?
CVE-2026-2701 is classified as a critical vulnerability due to its remote code execution capabilities.
2
How do I fix CVE-2026-2701?
To fix CVE-2026-2701, update the Progress ShareFile Storage Zones Controller to the latest patched version.
3
Who is affected by CVE-2026-2701?
Organizations using Progress ShareFile Storage Zones Controller are affected by CVE-2026-2701.
4
What type of vulnerability is CVE-2026-2701?
CVE-2026-2701 is a remote code execution (RCE) vulnerability.
5
What can happen if CVE-2026-2701 is exploited?
If CVE-2026-2701 is exploited, an authenticated user can upload and execute malicious files on the server.