Team D4rkn3ttz[verified]@Team_D4rkn3ttzActive Exploitation
CERT brief highlights alleged mass exploitation of CVE-2025-55182 on exposed Next.js hosts and a pre‑auth RCE chain in ShareFile, recommends patching exposed assets and tightening cloud auth monitoring.
Nicolas Krassas[verified]@DinosnDisclosure
The post announces a new pre‑authentication remote‑code‑execution vulnerability chain affecting Progress ShareFile, identified as CVE‑2026‑2699 and CVE‑2026‑2701.
yousukezan[verified]@yousukezanPatch
Progress ShareFile’s Storage Zones Controller v5 is affected by two critical CVEs (CVE‑2026‑2699 and CVE‑2026‑2701) that allow unauthenticated and authenticated attackers to modify settings or execute arbitrary code, but the vendor has already released a patch to mitigate these risks.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
An active exploitation chain involving CVE-2026-2699 and CVE-2026-2701 has compromised over 30,000 internet‑facing instances, with a patch released in March 2026.
SOCRadar®[verified]@socradarDisclosure
The post announces pre‑authentication remote code execution vulnerabilities (CVE‑2026‑2699/2701) in ShareFile, notes webshell risk, requires no credentials, and highlights a patch to version 5.12.4.
The Hacker News@TheHackersNewsDisclosure
Progress ShareFile's customer‑managed deployments are vulnerable to a pre‑auth RCE chain (CVE‑2026‑2699 and CVE‑2026‑2701), with roughly 30,000 internet‑facing instances affected; the issue is fixed in version 5.12.4.
Dhiyaneshwaran@DhiyaneshDKGeneral
A new authentication bypass CVE-2026-2699 is announced with a Nuclei detection rule and an external blog reference, but no exploit, patch, or detailed technical information is provided.
Densel@luckyhacker43Disclosure
The tweet announces newly discovered pre‑authentication remote code execution bugs (CVE‑2026‑2699/2701) in Progress ShareFile, linking to resources that likely contain PoC code, but does not mention active exploitation or patches.