CVE-2026-2699Disclosure(progress / sharefile_storage_zones_controller)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch progress sharefile_storage_zones_controller systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-698

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharefile_storage_zones_controller

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 55 mentions across 18 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 15 signals
  • Patch or workaround mentioned in 24 signals
  • Technical details provided in 49 signals
  • Disclosure: 26 classified signals
  • Peaked 17d ago at 17 mentions (2026-04-02); latest day: 1
  • 55 total mentions across 18 days

Affected systems

Vendors
Products
sharefile_storage_zones_controller

Deep dive

Activity timeline55 mentions / 18d
0491317Mentions · 2026-04-02: 17Mentions · 2026-04-03: 16Mentions · 2026-04-04: 1Mentions · 2026-04-05: 3Mentions · 2026-04-06: 1Mentions · 2026-04-07: 4Mentions · 2026-04-08: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Mentions · 2026-06-11: 1Mentions · 2026-07-11: 1Mentions · 2026-07-13: 2Mentions · 2026-07-14: 1Mentions · 2026-07-15: 1Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-04-02: 9PoC Mentioned / Linked · 2026-04-03: 5PoC Mentioned / Linked · 2026-06-11: 1Exploit Tool / Code · 2026-04-03: 2Active Exploitation · 2026-04-02: 3Active Exploitation · 2026-04-03: 2Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-07-13: 1Active Exploitation · 2026-07-15: 1Patch / Workaround · 2026-04-02: 8Patch / Workaround · 2026-04-03: 10Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-07-13: 2Technical Details · 2026-04-02: 17Technical Details · 2026-04-03: 15Technical Details · 2026-04-04: 1Technical Details · 2026-04-05: 3Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-25: 1Technical Details · 2026-06-11: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 2Technical Details · 2026-07-14: 1Technical Details · 2026-07-15: 1Technical Details · 2026-08-25: 104-0204-0304-0404-0504-0604-0704-0804-0904-1004-1304-2204-2506-1107-1107-1307-1407-1508-25
Signal classification5 categories
Disclosure
2647.3%
Patch
1120.0%
Active Exploitation
712.7%
General
610.9%
PoC
59.1%
Referenced assets43 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-0217
Active Exploitation3Disclosure7Patch3PoC4
2026-04-0316
Active Exploitation2Disclosure9General1Patch3PoC1
2026-04-041
Disclosure1
2026-04-053
Disclosure3
2026-04-061
Disclosure1
2026-04-074
Disclosure1General3
2026-04-081
Patch1
2026-04-091
General1
2026-04-101
General1
2026-04-131
Patch1
2026-04-221
Patch1
2026-04-251
Disclosure1
2026-06-111
Disclosure1
2026-07-111
Active Exploitation1
2026-07-132
Patch2
2026-07-141
Disclosure1
2026-07-151
Active Exploitation1
2026-08-251
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    Progress ShareFile has a pre-auth RCE chain affecting customer-managed deployments. CVE-2026-2699 (auth bypass) + CVE-2026-2701 (RCE) let attackers skip login, access admin endpoints, and upload web shells. ~30k internet-facing instances affected. Fixed in 5.12.4. 🔗 Exploit chain and impact → https://thehackernews.com/2026/04/threatsday-bulletin-pre-auth-chains.html#pre-auth-rce-chain-exposed

    Post summary

    Progress ShareFile's customer‑managed deployments are vulnerable to a pre‑auth RCE chain (CVE‑2026‑2699 and CVE‑2026‑2701), with roughly 30,000 internet‑facing instances affected; the issue is fixed in version 5.12.4.

    4291862711.9K
    1.6M followersView on X
  • Dhiyaneshwaran@DhiyaneshDK
    General

    🚨 CVE-2026-2699 - Progress ShareFile Storage Zone Controller - Authentication Bypass 🔍 Nuclei Template: https://cloud.projectdiscovery.io/library/CVE-2026-2699 📑 Reference: https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ #bugbounty #infosec #nuclei #hackwithautomation https://t.co/mOhMbUePfJ

    Post summary

    A new authentication bypass CVE-2026-2699 is announced with a Nuclei detection rule and an external blog reference, but no exploit, patch, or detailed technical information is provided.

    019080345.2K
    4.5K followersView on X
  • Densel@luckyhacker43
    Disclosure

    New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In ⚡️ 🔗 https://watchtowr.com/resources/progress-sharefile-storage-zone-controller-pre-auth-rce-cve-2026-2699-cve-2026-2701/ 🔗 https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ 🔗 https://cybersecuritynews.com/progress-sharefile-vulnerability/ Join team 👉https://t.me/luckyhacker43 https://t.co/R7dIqxnpED

    Post summary

    The tweet announces newly discovered pre‑authentication remote code execution bugs (CVE‑2026‑2699/2701) in Progress ShareFile, linking to resources that likely contain PoC code, but does not mention active exploitation or patches.

    04025101.1K
    2.8K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Disclosure

    We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02. @watchtowrcyber recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch! https://t.co/aVvl83pzt4

    Post summary

    The tweet announces that @watchtowrcyber disclosed an RCE exploit chain (CVE-2026-2699 and CVE-2026-2701) affecting Progress ShareFile, urges users to apply the latest patch, and provides brief technical details.

    1811335.7K
    21.8K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    We have also added CVE-2026-2699 tagging to our scans, which now detect unpatched Progress ShareFile instances. 120 IPs seen on 2026-04-06: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-2699%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on CVE-2026-2699 Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2026-2699%2B&data_set=count&scale=log&auto_update=on IP data in Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ https://t.co/2Xh5nIiFnV

    Post summary

    The post announces scanning for CVE‑2026‑2699 and reports a few IPs, but provides no PoC, exploit, patch, or technical details.

    0901233.4K
    21.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-2699 - critical 🚨 Progress ShareFile Storage Zones Controller - Authentication Bypass > Customer Managed ShareFile Storage Zones Controller (SZC) contains an authentication ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-2699 @pdnuclei #NucleiTemplates ...

    Post summary

    CVE-2026-2699 reveals a critical authentication bypass in Progress ShareFile Storage Zones Controller, but no PoC, exploit, or active exploitation information is provided.

    02083373
    960 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Progress ShareFile hit by critical 9.8 CVSS RCE flaws (CVE-2026-2699). Unauthenticated attackers can hijack configuration and execute code. Update to v5.12.4! #ShareFile #ProgressSoftware #RCE #CyberSecurity #InfoSec #PatchNow #CVE #DataSecurity #TechNews https://securityonline.info/progress-sharefile-rce-vulnerability-cve-2026-2699-storage-zones/ https://t.co/NvjrMF7o7r

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2026‑2699) in Progress ShareFile, notes that unauthenticated attackers can hijack configuration and execute code, and recommends applying the v5.12.4 update.

    010102704
    12.3K followersView on X
  • Team D4rkn3ttz@Team_D4rkn3ttz
    Active Exploitation

    IR/CERT Morning Brief Today’s priorities: alleged mass exploitation of CVE-2025-55182 affecting exposed Next.js hosts, a pre-auth ShareFile RCE chain (CVE-2026-2699 / CVE-2026-2701), and malware delivery following the Claude Code source leak. Also watching Iran-linked cloud password spraying. Bottom line: patch exposed web/file-sharing assets, protect dev/CI credentials, and tighten cloud auth monitoring. #cybersecurity #threatintel #IR #CERT

    Post summary

    CERT brief highlights alleged mass exploitation of CVE-2025-55182 on exposed Next.js hosts and a pre‑auth RCE chain in ShareFile, recommends patching exposed assets and tightening cloud auth monitoring.

    70030566
    320 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The post announces a new pre‑authentication remote‑code‑execution vulnerability chain affecting Progress ShareFile, identified as CVE‑2026‑2699 and CVE‑2026‑2701.

    000531.6K
    157.2K followersView on X
  • Florian Hansemann@CyberWarship
    Disclosure

    ''You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)'' #infosec #pentest #redteam #blueteam https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The tweet announces the discovery of a pre‑authentication remote code execution chain affecting Progress ShareFile (CVE-2026-2699 & CVE-2026-2701) and links to an article describing the vulnerability, but does not provide evidence of active exploitation, PoC, patch, or false positive claims.

    000331.3K
    88.4K followersView on X
  • /r/netsec@_r_netsec
    PoC

    You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The text points to a blog post that likely details a pre‑authentication Remote Code Execution chain for Progress ShareFile, providing CVE identifiers and suggesting a proof‑of‑concept exists, but it does not describe active exploitation, formal patches, or detailed exploit code.

    00041661
    33.3K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    Progress Software suspended ShareFile Storage Zone Controller accounts over a credible threat. CVE-2026-2699 (CVSS 9.8) may be involved. #ShareFile #ProgressSoftware #CVE20262699 #StorageZoneController #DataSecurity http://meterpreter.org/sharefile-zone-controller-shutdown/

    Post summary

    Progress Software halted ShareFile Storage Zone Controller accounts due to a credible threat potentially linked to the severe CVE‑2026‑2699, but no PoC, exploit code, active exploitation, or patches are disclosed.

    02011391
    12.5K followersView on X
  • ET Labs@ET_Labs
    General

    18 new OPEN, 67 new PRO (18 + 49) AuraC2, Lumma Stealer, NetSupport RAT, Progress ShareFile (CVE-2026-2699, CVE-2026-2701), XWorm, ZPHP Thanks @whoamix302 https://community.emergingthreats.net/t/ruleset-update-summary-2026-04-07-v11166/3257

    Post summary

    The update notes new Open/Pro entries and new Progress ShareFile CVEs without providing technical details, exploitation evidence, or mitigation information.

    02011372
    5.7K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Patch

    Top affected: US, Germany Patch: https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26 Note: we are just sharing exposed population, there is no vulnerability assessment Background: https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ CVE-2026-2699 NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-2699 CVE-2026-2701 NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-2701

    Post summary

    The message shares a public patch for ShareFile's CVE-2026-2699/2701 chain and references background material, but provides no evidence of active exploitation or a PoC.

    01021636
    21.8K followersView on X
  • yousukezan@yousukezan
    Patch

    企業向けファイル転送製品Progress ShareFileで重大な脆弱性が見つかり、未認証の攻撃者でもサーバーを乗っ取られる恐れが判明した。オンプレ環境に深刻な影響を与える可能性がある。 問題はStorage Zones Controller v5(顧客管理ゾーン)に存在し、watchTowrの調査で発覚した。CVE-2026-2699はCVSS 9.8の深刻度で、「リダイレクト後実行」により未認証のまま設定ページへアクセス可能となり、システム設定の改変や最終的なリモートコード実行に至る恐れがある。さらにCVE-2026-2701(CVSS 9.1)では、認証済みユーザーまたは侵入後の攻撃者が不正ファイルをアップロードし、検証不備を突いて任意コードを実行できる。これによりサーバー権限での完全な制御奪取が可能となる。ベンダーは修正アップデートを公開済みであり、迅速な適用が求められる。 https://securityonline.info/progress-sharefile-rce-vulnerability-cve-2026-2699-storage-zones/

    Post summary

    Progress ShareFile’s Storage Zones Controller v5 is affected by two critical CVEs (CVE‑2026‑2699 and CVE‑2026‑2701) that allow unauthenticated and authenticated attackers to modify settings or execute arbitrary code, but the vendor has already released a patch to mitigate these risks.

    010211.4K
    14.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    Progress ShareFileで認証バイパス+RCEのexploitチェーン😱 You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The content announces two pre‑authentication remote code execution vulnerabilities (CVE‑2026‑2699 & CVE‑2026‑2701) affecting Progress ShareFile, without providing PoC code, exploit tools, or patch information.

    110201.3K
    6.9K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Two Critical Remote Code Execution Vulnerabilities in #ShareFile Storage Zones Controller. CVE-2026-2699 CVE-2026-2701 CVSS: 9.8 CVSS 9.1. These two vulnerabilities chained together can lead to a full-system compromise. #RCE! #Patch #Patch #Patch

    Post summary

    The message warns of two critical RCE vulnerabilities in ShareFile Storage Zones Controller (CVE‑2026‑2699 and CVE‑2026‑2701) that can be chained for full‑system compromise, urging users to apply patches.

    02010351
    7.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Progress ShareFile Storage Zone Controller hit with critical pre-auth RCE chain. CVE-2026-2699 authentication bypass combined with CVE-2026-2701 RCE enables complete compromise of 30,000+ internet-facing instances. Technical breakdown: • CVE-2026-2699: Execution After Redirect (CWE-698) in /ConfigService/Admin.aspx - Response.Redirect() called with 'false' parameter allows code execution to continue after redirect • CVE-2026-2701: File upload path manipulation + ZIP extraction abuse enables webshell deployment to webroot directory • Attack chain: Bypass auth → modify Zone configuration → change storage path to webroot → upload ZIP with ASPX webshell → extract via unzip=true parameter • Affects StorageCenter 5.x branch (http://ASP.NET), patched in version 5.12.4 released March 10, 2026 DFIR artifacts: • HTTP 302 responses with >10,000 character body from /ConfigService/Admin.aspx • Modifications to Zone configuration files and storage repository settings • Unusual ZIP uploads to /upload.aspx with unzip=true parameter • ASPX files extracted to webroot directories (C:\inetpub\wwwroot\ShareFile\) Hunt for HTTP requests to /ConfigService/Admin.aspx returning 302 with large response bodies, and monitor for unexpected file uploads to administrative endpoints. #DFIR_Radar

    Post summary

    An active exploitation chain involving CVE-2026-2699 and CVE-2026-2701 has compromised over 30,000 internet‑facing instances, with a patch released in March 2026.

    10011350
    1.7K followersView on X
  • Arctic Wolf@AWNetworks
    Patch

    Progress ShareFile has released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x, tracked as CVE-2026-2699 and CVE-2026-2701. Learn more in our latest security bulletin: https://arcticwolf.com/resources/blog/cve-2026-2699-cve-2026-2701/?utm_source=Twitter&utm_medium=social&utm_campaign=ADV%20FY26%20Social%20Twitter

    Post summary

    The advisory announces that Midpoint ShareFile Storage Zones Controller 5.x has received patches for two critical CVEs, with a link to a detailed security bulletin.

    02000234
    4.5K followersView on X
  • SOCRadar®@socradar
    Disclosure

    🚨 ShareFile flaws CVE-2026-2699 & 2701 enable pre-auth #RCE. 🔹 No credentials needed 🔹 Webshell risk 🔹 Patch to 5.12.4 🔍 https://socradar.io/blog/progress-sharefile-cve-2026-2699-2701-rce/

    Post summary

    The post announces pre‑authentication remote code execution vulnerabilities (CVE‑2026‑2699/2701) in ShareFile, notes webshell risk, requires no credentials, and highlights a patch to version 5.12.4.

    01010258
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogresssharefile_storage_zones_controller---

Explore more