logo

New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In

ID: af6558bf-f701-5584-a9ed-47a7f354a6c7

STIX ID: report--af6558bf-f701-5584-a9ed-47a7f354a6c7

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-04

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical attack chain affecting Progress ShareFile Storage Zones Controller 5.x lets unauthenticated attackers reach admin pages (auth bypass) and upload/extract malicious archives to web-accessible paths, enabling remote code execution and webshell placement (CVE-2026-2699, CVE-2026-2701). Progress released fixes (5.12.4 and 6.x) and defenders are advised to identify exposed controllers, apply patches immediately, and inspect for configuration changes and unexpected files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.