Vulnerabilities Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns The company notified customers to manually shut down their servers while it is investigating a credible threat. By Ionut Arghire | July 13, 2026 (4:20 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Enterprise software giant Progress Software on Friday prompted ShareFile customers to shut down Storage Zone Controller servers amid security concerns. A Storage Zone Controller provides ShareFile customers with private data storage, either on-premises or on a third-party storage system, that is protected with an application-specific password and is self-managed. On Friday, the company notified customers that it had disabled access to ShareFile accounts using the Storage Zone Controllers and that it is investigating a âcredible external security threatâ. âWe are aware of a credible external security threat targeting Progress ShareFile Storage Zone Controllers,â a message on the companyâs forums reads. Progress also told customers that, as an additional protection measure, they should manually shut down their Storage Zone Controllers. âPlease manually shut down the server hosting your Storage Zone Controllers as soon as possible while Progress continues its assessment with cybersecurity experts,â the companyâs message reads. Advertisement. Scroll to continue reading. In a private communication sent to customers, Progress said the access restrictions were temporary, but did not provide details on when the issue would be resolved. âAt this time, we do not indicate unauthorized access to any Progress ShareFile accounts or customer data,â the company said. Progress has not shared details about the security threat, but users speculate that threat actors might be targeting two vulnerabilities addressed in March. The flaws, tracked as CVE-2026-2699 (CVSS score of 9.8) and CVE-2026-2701 (CVSS score of 9.1), could be chained together to make configuration changes and upload malicious files to achieve remote code execution (RCE) without authentication. SecurityWeek has emailed Progress for a statement on the matter and will update this article if the company responds. Related: Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws Related: Critical Gitea Flaw Under Active Exploitation, Researchers Warn Related: Critical Adobe ColdFusion Vulnerability Exploited in Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Network of 200 GitHub Repositories Used for Malware Infection 12 Million Impacted by Data Breach at Japanese Telco KDDI 15-Year-Old Linux Vulnerability âGhostLockâ Earns Researchers $92k From Google Mount Royal University Confirms Data Stolen in Ransomware Attack Chrome 150 Update Patches 27 Vulnerabilities 8Layers Raises $2.9 Million for Identity Security Platform Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices Accenture Confirms Data Breach After Hacker Claims Source Code Theft Latest News Centers Laboratory Data Breach Affects 540,000 Individuals Ghost Accounts Abuse GitHub API in Mass Recon Campaign In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Third US Security Expert Sentenced to Prison for Helping Ransomware Gang China, India-Linked Hackers Both Targeted Same Pakistani Police Force Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers GigaWiper Combines Multiple Malware for System-Level Sabotage âHalluSquattingâ Turns AI Hallucinations Into Botnet Delivery Mechanism Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 16, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the Move BlueVoyant has appointed Ravi Subramanian as CFO and Jamie Coleman as CCO. Solana Foundation has appointed Michael Coates as Chief Information Security Officer. Michael Sikorski has joined Coinbase as Chief Information Security Officer. More People On The Move Expert Insights The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) When Information Becomes the Attack Surface â Understanding AI Agent Traps From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Progress Software has issued a shutdown order for ShareFile Storage Zone Controllers due to a credible external threat, likely involving two critical vulnerabilities, CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1). These flaws affect Storage Zone Controller versions 5.0.0 through 5.11.x and can be chained to achieve unauthenticated remote code execution. The fixed version is 5.12.4; until an assessment is complete, the immediate workaround is to manually shut down the server hosting the Storage Zone Controller.