← Progress Software (MOVEit)

2026 Progress ShareFile — Storage Zone zero-day (CVE pending); precautionary shutdown (Jul 10–14)

2026 Unknown records affected Share on X

Data compromised

Progress stated no indication of unauthorized access to ShareFile accounts or customer data at Jul 14, 2026 update; flaw could allow authenticated admin read/write of server filesystem per BleepingComputer

Technical writeup

Verified vendor security incident — July 10–14, 2026. Progress Software emailed ShareFile customers using on-premises Storage Zone Controllers to shut down Windows servers after a credible external security threat. On July 14, 2026 Progress confirmed a high-severity path traversal flaw affecting Storage Zone Controller 5.x and 6.x versions, allowing an authenticated administrative user to read arbitrary files, write attacker-controlled content, or enumerate the server filesystem. Progress reserved a CVE identifier for publication and released patched versions 5.12.5 and 6.0.2. The company stated it currently has no indication customers were breached. BreachHistory indexes recordsAffected 0 pending any attested victim count.

Root cause

High-severity path traversal vulnerability in ShareFile Storage Zone Controller 5.x/6.x identified after credible external threat warning; Progress released patches 5.12.5 and 6.0.2—no customer breach confirmed at Jul 14 update

References