logo

New Progress ShareFile flaws can be chained in pre-auth RCE attacks

ID: 4bd7112c-38ad-59f3-99bb-6ea44b8fa0c9

STIX ID: report--4bd7112c-38ad-59f3-99bb-6ea44b8fa0c9

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Progress ShareFile Storage Zone Controller (branch 5.x) contains two chained flaws—an authentication bypass (CVE-2026-2699) and an RCE via file upload/extraction (CVE-2026-2701)—that together allow an attacker to gain admin access, change storage zone settings and secrets, and drop ASPX webshells to exfiltrate files; Progress released patches in 5.12.4 (Mar 10), researchers estimate large internet exposure (~30,000 SZC instances) but reported no observed in-the-wild exploitation at time of disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.