Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in March, could be exploited to gain remote code execution and potentially compromise customer data. This action is being taken as Progress investigates the threat with cybersecurity experts.
Progress Software has issued a critical directive to ShareFile customers, demanding the immediate shutdown of their Storage Zone Controller servers. These controllers provide a private data storage solution for ShareFile users, utilizing application-specific passwords and self-management. The company’s action follows a notification that it is investigating a ‘credible external security threat’ targeting these controllers.
Progress stated that it suspects the threat stems from two vulnerabilities, CVE-2026-2699 (CVSS score of 9.8) and CVE-2026-2701 (CVSS score of 9.1), which could be linked together to allow attackers to make configuration changes and upload malicious files, ultimately achieving remote code execution (RCE) without needing authentication. The company has not yet disclosed specifics about the nature of the threat, but users are speculating that threat actors are leveraging these vulnerabilities.
Progress has advised customers to manually shut down their Storage Zone Controllers as quickly as possible while the company continues its assessment with cybersecurity experts. The company indicated that at this time, it does not believe any customer accounts or data have been accessed, but the risk remains due to the potential for exploitation.
Progress has not yet responded to SecurityWeek’s request for further information on the incident. This situation is related to other recent security alerts, including a backdoor in Tenda firmware and critical flaws in ColdFusion, Langflow, and Joomla.