CVE-2026-16139 affects Progress ShareFile Storage Zones Controller versions 5.12.5 and earlier, and 6.0.2 and earlier. An authenticated zone administrator can exploit improper validation in the download preparation…
3 articles · Updated August 17, 2026
Recent Intelligence Reports
CVE-2026-16139: Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution [HIGH] CVSS 7.2 Exploit Intelligence - Recent CVEs / 11h In Progress ShareFile Storage Zones Controller versions <=5.12.5 and <=6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remot— exploit-intel.com · August 18, 2026