Cisecurity Critical Vulnerabilities in Progress ShareFile Enable Unauthenticated File Exfiltration
Article Content
- •Two critical vulnerabilities in Progress ShareFile allow unauthenticated file exfiltration.
- •Approximately 30,000 instances of ShareFile are exposed to the public internet.
- •Organizations are urged to patch immediately following the release of version 5.12.4.
Two critical vulnerabilities, CVE-2026-2699 and CVE-2026-2701, have been identified in Progress ShareFile's Storage Zones Controller, allowing unauthenticated attackers to perform remote code execution and potentially exfiltrate files. The vulnerabilities can be chained, starting with an authentication bypass that grants access to the admin interface, followed by remote code execution through file upload functionality. Approximately 30,000 instances of Progress ShareFile are exposed on the internet, with around 700 identified by the ShadowServer Foundation. Progress has released a patch in version 5.12.4 on March 10, 2026, addressing these vulnerabilities. No active exploitation has been reported yet, but the public disclosure raises concerns about potential attacks. Organizations using affected versions are urged to apply the patch immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track Clop, Progress Software and CVE-2026-2699 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Kiteworks Issues Urgent Shutdown Advisory Amid Zero-Day Threat Kiteworks has alerted its customers to shut down their servers due to credible threat intelligence indicating an imminent cyberattack exploiting a zero-day vulnerability. The advisory, which applies globally, recommends a six-hour shutdown window starting September 26, 2026. This precautionary measure comes as…