CVE-2026-16139: Remote Code Execution Risk in ShareFile Storage Zones Controller

CVE-2026-16139: Remote Code Execution Risk in ShareFile Storage Zones Controller

First seen 17 Aug 2026, 22:47 UTC Feedlyexploit-intel.comnvd.nist.govvulners.comvuldb.com 92% similarity 61.5

Article Content

Browse articles
ThreatCluster

CVE-2026-16139 affects Progress ShareFile Storage Zones Controller versions 5.12.5 and earlier, and 6.0.2 and earlier. An authenticated zone administrator can exploit improper validation in the download preparation flow, allowing attacker-controlled files to be written outside the intended directory. This vulnerability can lead to remote code execution in v5 versions, although exploitation on v6 versions is unconfirmed. The CVSS score for this vulnerability is 7.2, indicating a high severity level. No public proof-of-concept or confirmed exploitation has been reported as of now. Users are advised to upgrade to versions newer than 5.12.5 for v5 and 6.0.2 for v6, and to restrict zone administrator privileges. Monitoring file system activity for unexpected writes is also recommended.

Key Points: • CVE-2026-16139 allows remote code execution in affected ShareFile versions. • No confirmed exploitation or public proof-of-concept exists yet. • Users should upgrade to the latest versions and monitor file system activity.

ThreatCluster AI How this analysis works

Timeline

2026-08-17
CVE-2026-16139 published
Progress disclosed a vulnerability in ShareFile Storage Zones Controller affecting versions 5.12.5 and 6.0.2.
Feedly
2026-08-18
NVD entry created for CVE-2026-16139
The National Vulnerability Database published details on CVE-2026-16139, confirming its severity and potential impact.
nvd.nist.gov
2026-08-18
Exploit Intelligence reports on CVE-2026-16139
Exploit Intelligence highlighted the arbitrary file write vulnerability and its implications for remote code execution.
exploit-intel.com

Community

Browse all →