ZeroHour

CVE-2026-2699

PoC moderate

Unauthenticated RCE in Progress ShareFile Storage Zones Controller

CVSS 3.1
9.8 critical
EPSS
60%p99
Published
()
Modified
AI analysis

CVE-2026-2699 is an improper access control flaw (CWE-284) in customer-managed Progress ShareFile Storage Zones Controller (SZC) that lets an unauthenticated attacker reach restricted configuration pages over the network. Because the issue is reachable pre-authentication with no user interaction and low complexity (AV:N/AC:L/PR:N), an attacker needs only network access to an exposed controller. Successful abuse allows the attacker to change system configuration and potentially escalate to full remote code execution, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 9.8). Any organization running its own customer-managed SZC deployment is affected; the Progress/ShareFile-hosted cloud service itself is not the flaw, though Progress has taken precautionary emergency action (disabling ShareFile accounts and urging customers to shut down controllers) amid an active security threat per press reports. A public proof-of-concept exploit is available (watchTowr Labs), the flaw carries a very high EPSS of 59.5% (99th percentile) indicating strong likelihood of exploitation within 30 days, and it is not yet listed in CISA KEV.

What to do: Apply the vendor patch as soon as possible per the Progress security bulletin (the fixed version is not specified in the available data). As interim mitigation, restrict unauthenticated internet access to the SZC configuration interface (e.g., firewall or reverse-proxy rules) and consider temporarily taking the controller offline if immediate patching is not possible, as Progress has advised. Review logs for unauthenticated requests to configuration pages and signs of configuration changes or follow-on command execution.

Affected
Progress ShareFile Storage Zones Controller (customer-managed deployments)
Estimated exposure
moderate~1,000-10,000 internet-exposed Storage Zones Controller instances — Only a subset of ShareFile customers self-host a customer-managed SZC, and public internet scans/certificate-based censuses of ShareFile SZC endpoints have historically shown low thousands of exposed hosts, suggesting on the order of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

Vendors
progress
Products
sharefile storage zones controller
Weakness
CWE-284, CWE-698
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news