ZeroHour

CVE-2026-2701

moderate

Authenticated File-Upload RCE in Progress ShareFile Storage Zones Controller

CVSS 3.1
8.8 high
EPSS
55%p99
Published
()
Modified
AI analysis

CVE-2026-2701 is a remote code execution flaw in Progress ShareFile Storage Zones Controller in which an authenticated user can upload a malicious file to the server and have it executed, with the flaw mapped to unrestricted file upload (CWE-434), OS command injection (CWE-78), and code injection (CWE-94). It is triggered over the network by any holder of a low-privileged authenticated account (CVSS AV:N/PR:L) who uploads a crafted file, with no user interaction required. Successful exploitation yields code execution on the hosting server with high impact to confidentiality, integrity, and availability, potentially exposing stored ShareFile customer data and providing a foothold in the corporate network. Any organization running the self-hosted Storage Zones Controller is affected, though the data does not specify whether SaaS-only ShareFile usage is impacted. No public PoC exists and the issue is not yet in CISA KEV, but EPSS assigns a 54.5% probability of exploitation within 30 days, and news reports indicate Progress has disabled ShareFile accounts and urged customers to shut down their servers, signaling vendor-perceived urgency.

What to do: No fixed version is listed in the available data, so monitor the Progress advisory for a patched Storage Zones Controller release and apply it as soon as it is published; until then, follow Progress's guidance (reports say it disabled ShareFile accounts and urged customers to shut down Storage Zones servers) or restrict the controller's internet exposure to trusted networks. Review servers for unexpected uploaded files, unfamiliar processes, and anomalous authenticated upload activity in logs, and rotate credentials for accounts with access to the controller.

Affected
Progress ShareFile Storage Zones Controller
Estimated exposure
moderate≈1,000–10,000 internet-exposed Storage Zones Controller servers; total on-prem deployments likely in the low tens of thousands — Based on public internet scans that have historically shown a few thousand exposed ShareFile Storage Zones Controller instances, combined with the product's niche enterprise self-hosted deployment pattern among organizations requiring…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Vendors
progress
Products
sharefile storage zones controller
Weakness
CWE-78, CWE-94, CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news