Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. Last week, Progress urged customers using ShareFile Storage Zone Controllers to immediately shut down their Windows servers after receiving a warning of a "credible external security threat." At the time, the company temporarily disabled access to all ShareFile accounts using Storage Zone Controllers while it investigated the incident with cybersecurity experts. "We acted out of an abundance of caution after we received information from a credible source of a potential threat to the SZC. Our investigation then revealed a vulnerability that we promptly patched before it was publicly known," Progress told BleepingComputer. In an update sent to customers today, Progress says its investigation identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller. "An authenticated administrative user can read arbitrary files accessible to the application's service account, write threat actor-controlled content to arbitrary directories or enumerate the server filesystem layout," reads an email seen by BleepingComputer. Progress says a CVE identifier has been reserved for the vulnerability, and it will be published in two weeks. When asked why there was a delay, Progress told BleepingComputer that waiting to publish t...
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
BleepingComputer
·Lawrence Abrams
·Published Jul 14, 2026
·Updated
Affected Software
1 affected component
Progress Software ShareFile Storage Zone Controller>=5.0<=5.999, >=6.0<=6.999
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a confirmed zero-day vulnerability in Progress Software's ShareFile that led to the emergency shutdown of Storage Zone Controllers.
2
What security implications are discussed in the article?
The article highlights the high-severity nature of the zero-day vulnerability and the immediate risk it posed to users of ShareFile Storage Zone Controllers.
3
What actions did Progress Software take in response to the vulnerability?
Progress Software released security updates to patch the zero-day vulnerability affecting ShareFile Storage Zone Controllers.
4
What products are affected by the zero-day flaw?
The affected product is Progress Software's ShareFile Storage Zone Controller.
5
What should users of ShareFile Storage Zone Controllers do in light of this news?
Users are urged to immediately apply the security updates provided by Progress Software to protect against the vulnerability.