logo

Progress ShareFile Flaws CVE-2026-2699 & CVE-2026-2701 RCE

ID: 5b267dae-5d0b-50a4-9a90-cc30fcacc7b6

STIX ID: report--5b267dae-5d0b-50a4-9a90-cc30fcacc7b6

Feed Name: SOCRadar Blog

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**Progress ShareFile pre-auth RCE chain:** Public disclosure shows CVE-2026-2699 (auth bypass, CVSS 9.8) can be chained with CVE-2026-2701 (RCE, CVSS 9.1) to allow unauthenticated placement of an ASPX webshell on customer-managed Storage Zones Controller 5.x instances; organizations should upgrade to ShareFile 5.12.4 or later and hunt for signs of webshells or suspicious upload/extraction activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.