Vulnerabilities Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. By Ionut Arghire | July 15, 2026 (5:48 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Progress Software has confirmed that a zero-day vulnerability was behind the recent ShareFile Storage Zones Controller disruption and that access to the service is being restored. The confirmation comes two days after the company disabled access to ShareFile accounts for all customers using Storage Zones Controllers, citing âa credible external security threatâ. âAs of Tuesday, July 14th, access has been restored for Progress ShareFile Storage Zones Controller customers following the service disruption we communicated previously,â Progress told SecurityWeek . The company explained that it prompted customers to shut down their servers running Storage Zones Controllers due to a high-severity vulnerability in versions 5.x and 6.x of the product. âWe developed and released patched versions to customers, and once patched, these customersâ Storage Zones Controllers will be operational,â Progress said. The company has not shared details on the vulnerability and has yet to respond to SecurityWeekâs follow-up questions, but said it is not aware of any customer compromise. Advertisement. Scroll to continue reading. âAt this time, we have no evidence of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat,â the company said. In private communication to its customers, Progress said that the security defect is a path traversal bug exploitable by attackers with administrative privileges. âAn authenticated administrative user can read arbitrary files accessible to the applicationâs service account, write threat actor-controlled content to arbitrary directories, or enumerate the server filesystem layout,â a copy of the email shared on Reddit reads. According to WatchTowr founder and CEO Benjamin Harris, Progressâs description of the issue and its withholding of details suggest there might be more to the story. âVulnerabilities that already assume an attacker has administrative access do not typically trigger such an aggressive response. So whatâs the missing piece? Is there more to the attack than has been disclosed? Has Progress observed attacker activity that warrants a more aggressive response?â Harris said. Defenders are advised to assume the worst, to update their ShareFile Storage Zone Controllers immediately, and to assume that exposed systems may have been compromised. âDonât assume that installing a patch is the end of the story. When a vendor tells customers to disconnect servers from the internet and then ships a patch days later, for an admin-only exploitable vulnerability no less, no one will be blamed for pondering,â Harris said. Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Related: SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud Related: RabbitMQ Vulnerability Threatens Enterprise Systems Related: 15-Year-Old Linux Vulnerability âGhostLockâ Earns Researchers $92k From Google Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Multiple Jscrambler Packages Impacted by Supply Chain Attack RabbitMQ Vulnerability Threatens Enterprise Systems Zimbra Patches Critical Code Execution Vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Ghost Accounts Abuse GitHub API in Mass Recon Campaign Latest News ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims Adobe Patches Critical ColdFusion Vulnerabilities 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 15, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the Move F5 has appointed Cathy Peterman as Chief People Officer. Sean Murphy has joined F5 as a Field Chief Information Security Officer - North America. CodeHunter has appointed Stephen McCarney as Chief Strategy Officer. More People On The Move Expert Insights The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) When Information Becomes the Attack Surface â Understanding AI Agent Traps From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email
Progress Software has confirmed a zero-day path traversal vulnerability (CVE not provided) in ShareFile Storage Zones Controllers versions 5.x and 6.x, exploitable by authenticated administrative users to read arbitrary files, write content, or enumerate the server filesystem. The company has released patched versions and restored access for customers who apply them, but advises defenders to update immediately and assume exposed systems may have been compromised, as the aggressive response suggests potential undisclosed attacker activity.