logo

New Progress ShareFile Flaws Expose Servers to Unauthorized Remote Takeover

ID: 4f64807e-d74a-5e48-ba22-0621e1b226db

STIX ID: report--4f64807e-d74a-5e48-ba22-0621e1b226db

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Divya

...
...

WatchTowr Labs disclosed two critical vulnerabilities in the on-premises Progress ShareFile Storage Zone Controller (Branch 5.x) — an authentication bypass (CVE-2026-2699) caused by an "Execution After Redirect" coding error and a follow-on RCE (CVE-2026-2701) that allows attackers to reconfigure the storage location to the webroot and upload an ASPX web shell. Roughly 30,000 instances are exposed publicly; Progress released fixes in version 5.12.4 on March 10, 2026, and organizations are urged to patch immediately and monitor webroots and configuration endpoints for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.