• News/
  • bleepingcomputer-20260714160847

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

BleepingComputer
·
Lawrence Abrams
·
Published Jul 14, 2026
·
Updated

Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. Last week, Progress urged customers using ShareFile Storage Zone Controllers to immediately shut down their Windows servers after receiving a warning of a "credible external security threat." At the time, the company temporarily disabled access to all ShareFile accounts using Storage Zone Controllers while it investigated the incident with cybersecurity experts. "We acted out of an abundance of caution after we received information from a credible source of a potential threat to the SZC. Our investigation then revealed a vulnerability that we promptly patched before it was publicly known," Progress told BleepingComputer. In an update sent to customers today, Progress says its investigation identified a high-severity path traversal vulnerability affecting all 5.x and 6.x versions of ShareFile Storage Zone Controller. "An authenticated administrative user can read arbitrary files accessible to the application's service account, write threat actor-controlled content to arbitrary directories or enumerate the server filesystem layout," reads an email seen by BleepingComputer. Progress says a CVE identifier has been reserved for the vulnerability, and it will be published in two weeks. When asked why there was a delay, Progress told BleepingComputer that waiting to publish t...

Read full article

Affected Software

1 affected component
Progress Software ShareFile Storage Zone Controller>=5.0<=5.999, >=6.0<=6.999
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a confirmed zero-day vulnerability in Progress Software's ShareFile that led to the emergency shutdown of Storage Zone Controllers.

2

What security implications are discussed in the article?

The article highlights the high-severity nature of the zero-day vulnerability and the immediate risk it posed to users of ShareFile Storage Zone Controllers.

3

What actions did Progress Software take in response to the vulnerability?

Progress Software released security updates to patch the zero-day vulnerability affecting ShareFile Storage Zone Controllers.

4

What products are affected by the zero-day flaw?

The affected product is Progress Software's ShareFile Storage Zone Controller.

5

What should users of ShareFile Storage Zone Controllers do in light of this news?

Users are urged to immediately apply the security updates provided by Progress Software to protect against the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203