logo

Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile

ID: 062aeff6-5980-56e1-88c9-8c311fd801da

STIX ID: report--062aeff6-5980-56e1-88c9-8c311fd801da

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

A pair of critical vulnerabilities in Progress ShareFile Storage Zones Controller v5 were disclosed: CVE-2026-2699 (CVSS 9.8) allows unauthenticated attackers to bypass restrictions and access configuration pages leading to potential remote code execution, and CVE-2026-2701 (CVSS 9.1) permits authenticated users (or attackers who gained access via the first flaw) to upload and execute malicious files. Progress has released fixes in version 5.12.4 and recommends migrating to v6, which is not affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.