2026 Progress ShareFile — Storage Zone zero-day (CVE pending); precautionary shutdown (Jul 10–14)
Data compromised
Progress stated no indication of unauthorized access to ShareFile accounts or customer data at Jul 14, 2026 update; flaw could allow authenticated admin read/write of server filesystem per BleepingComputer
Technical writeup
Verified vendor security incident — July 10–14, 2026. Progress Software emailed ShareFile customers using on-premises Storage Zone Controllers to shut down Windows servers after a credible external security threat. On July 14, 2026 Progress confirmed a high-severity path traversal flaw affecting Storage Zone Controller 5.x and 6.x versions, allowing an authenticated administrative user to read arbitrary files, write attacker-controlled content, or enumerate the server filesystem. Progress reserved a CVE identifier for publication and released patched versions 5.12.5 and 6.0.2. The company stated it currently has no indication customers were breached. BreachHistory indexes recordsAffected 0 pending any attested victim count.
Root cause
High-severity path traversal vulnerability in ShareFile Storage Zone Controller 5.x/6.x identified after credible external threat warning; Progress released patches 5.12.5 and 6.0.2—no customer breach confirmed at Jul 14 update
References
- https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/
- https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/
- https://support.sharefile.com/s/article/ShareFile-Storage-Zone-Controller-Downloads
- https://www.progress.com/sharefile