https://reddit.com/r/cybersecurity/comments/1saecrr/youre_not_supposed_to_sharefile_with_everyone/: You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs
Published Apr 2, 2026
·Updated
Affected Software
1 affected component
Progress ShareFile
Frequently Asked Questions
1
What is the severity of CVE-2026-2699?
CVE-2026-2699 is classified as a critical vulnerability that allows for pre-authentication remote code execution.
2
How do I fix CVE-2026-2699?
To fix CVE-2026-2699, apply the security patches provided by Progress for the affected version of ShareFile.
3
What is CVE-2026-2701?
CVE-2026-2701 is a related vulnerability that also affects Progress ShareFile, potentially allowing arbitrary file uploads.
4
How can I determine if my Progress ShareFile installation is vulnerable to CVE-2026-2699 and CVE-2026-2701?
You can determine vulnerability by checking your Progress ShareFile version against the vendor's advisory for these CVEs.
5
Are there workarounds for CVE-2026-2699 before a patch can be applied?
Temporary workarounds for CVE-2026-2699 may include restricting access to vulnerable endpoints and monitoring for unusual activity.