New Progress ShareFile Flaws Expose Servers to Unauthorized Remote Takeover
ID: 4f64807e-d74a-5e48-ba22-0621e1b226db
STIX ID: report--4f64807e-d74a-5e48-ba22-0621e1b226db
Feed Name: GBHackers
WatchTowr Labs disclosed two critical vulnerabilities in the on-premises Progress ShareFile Storage Zone Controller (Branch 5.x) — an authentication bypass (CVE-2026-2699) caused by an "Execution After Redirect" coding error and a follow-on RCE (CVE-2026-2701) that allows attackers to reconfigure the storage location to the webroot and upload an ASPX web shell. Roughly 30,000 instances are exposed publicly; Progress released fixes in version 5.12.4 on March 10, 2026, and organizations are urged to patch immediately and monitor webroots and configuration endpoints for suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
