- July 10, 2026
Emerging Threat: Progress Customers Instructed to Shut Down Storage Zone Controllers
Progress Software issued an emergency communication via email to customers, urging immediate server shutdown citing a “credible external security threat targeting Progress Software’s ShareFile Storage Zone Controllers.”
Executive Summary
Update July 14, 2026: Progress ShareFile has confirmed a high severity path traversal vulnerability affecting ShareFile Storage Zones Controller versions 5.x and 6.x. The vulnerability could allow an authenticated administrative user to read arbitrary files accessible to the application’s service account, write attacker-controlled content to arbitrary directories, and enumerate the servers filesystem.
Progress Software has released patched versions 5.12.5 and 6.0.2 and is urging customers to upgrade as soon as possible. At the time of this update, a CVE has been reserved but is not publicly published. During investigation Progress Software states that it has found no evidence of unauthorized access to ShareFile customer accounts or data and has not identified an active threat. Relevant sections of this advisory have been updated accordingly.
Beazley Security has been made aware of an emerging threat targeting Progress Software ShareFile. Progress Software issued an emergency communication via email to customers, urging immediate server shutdown citing a “credible external security threat targeting Progress Software’s ShareFile Storage Zone Controllers.” Progress Software have also reportedly temporarily disabled Storage Zone Controller (SZC) based accounts while the investigation is underway.
At the time of writing, Progress Software have not released any technical details about the threat, or whether a zero-day vulnerability is involved. This warning follows the public April 2026 disclosure of two critical vulnerabilities tracked as CVE-2026-2699 and CVE-2026-2701 which when chained allowed unauthenticated remote code execution on exposed SZC servers.
Progress Software further warns “You must manually shut down the server hosting your Storage Zone Controllers. This is a critical additional step to ensure the safety of your data,” indicating that cloud-side management capabilities or mitigation options are not currently available to protect on-premises SZC deployments.
Given the sensitive nature of data hosted on these systems and confirmed credible threat from Progress Software, Beazley Security recommends following vendor guidance to disable controllers and reduce risk until fixes can be applied. This is an evolving situation, and Beazley Security will update this advisory as additional details become available.
Affected Systems or Products
Product | Affected Version | Fixed Version |
ShareFile Storage Zones Controller v5 | 5.12.4 and prior | 5.12.5 |
ShareFile Storage Zones Controller v6 | 6.0.1 and prior | 6.0.2 |
Mitigations / Workarounds
Progress stated that as a precaution, they have temporarily disabled access to ShareFile accounts using SZCs. However, Progress is instructing customers to manually shut down Windows servers hosting SZCs as a required additional mitigation step.
Update July 14th, 2026: Fixes have been made available by Progress, and can be applied to operationalize Storage Zone Controllers.
Patches
The latest Progress Software communication states that fixes have been made available for ShareFile Storage Zones Controller v5 and v6. According to documentation, software installers can be downloaded directly from ShareFile’s downloads page, which will require an active account.
Assistance can be asked for by opening a technical support case at support.sharefile.com.
Technical Details
The ShareFile Storage Zone Controller is an application that allows a client to host files on their own infrastructure but share them with the Progress ShareFile interface.
The email sent to clients indicates they believe the controllers are being targeted in a cyber attack, and that they have disabled ShareFile account access to these controllers in response. Because the system involves file servers hosted by clients, Progress has instructed clients to shut down their associated on-premises file servers as well.
Update July 14th, 2026: Progress ShareFile confirmed a high severity path traversal vulnerability within SZC’s and at the time of this update, “have no indication of unauthorized access to any ShareFile customer account or data” and have not identified an active threat. A CVE has been reserved and will be made public in two weeks, according to their latest communication to clients.
Beazley Security will continue to monitor the situation and update this advisory if other critical details become available.
How Beazley Security is responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.
We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.
If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.