CVE-2026-2701Disclosure(progress / sharefile_storage_zones_controller)

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch progress sharefile_storage_zones_controller systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-94CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharefile_storage_zones_controller

Threat summary

  • Active exploitation appears in 8 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 44 mentions across 14 observed days

What's happening

  • Active exploitation reported across 8 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 14 signals
  • Patch or workaround mentioned in 19 signals
  • Technical details provided in 40 signals
  • Disclosure: 19 classified signals
  • Peaked 13d ago at 17 mentions (2026-04-02); latest day: 1
  • 44 total mentions across 14 days

Affected systems

Vendors
Products
sharefile_storage_zones_controller

Deep dive

Activity timeline44 mentions / 14d
0491317Mentions · 2026-04-02: 17Mentions · 2026-04-03: 13Mentions · 2026-04-04: 1Mentions · 2026-04-05: 2Mentions · 2026-04-06: 1Mentions · 2026-04-07: 2Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Mentions · 2026-06-11: 1Mentions · 2026-07-11: 1Mentions · 2026-07-13: 1PoC Mentioned / Linked · 2026-04-02: 7PoC Mentioned / Linked · 2026-04-03: 4PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-25: 1PoC Mentioned / Linked · 2026-06-11: 1Exploit Tool / Code · 2026-04-03: 1Exploit Tool / Code · 2026-06-11: 1Active Exploitation · 2026-04-02: 3Active Exploitation · 2026-04-03: 3Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-07-13: 1Patch / Workaround · 2026-04-02: 8Patch / Workaround · 2026-04-03: 6Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-04-02: 17Technical Details · 2026-04-03: 12Technical Details · 2026-04-04: 1Technical Details · 2026-04-05: 2Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-25: 1Technical Details · 2026-06-11: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 104-0204-0304-0404-0504-0604-0704-0904-1004-1304-2204-2506-1107-1107-13
Signal classification6 categories
Disclosure
1943.2%
Patch
818.2%
Active Exploitation
715.9%
PoC
511.4%
General
36.8%
Exploit
24.5%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-0217
Active Exploitation2Disclosure9Exploit1General1Patch2PoC2
2026-04-0313
Active Exploitation3Disclosure6Exploit1Patch3
2026-04-041
Disclosure1
2026-04-052
Disclosure1Patch1
2026-04-061
Disclosure1
2026-04-072
General1PoC1
2026-04-091
General1
2026-04-101
Disclosure1
2026-04-131
Patch1
2026-04-221
Patch1
2026-04-251
PoC1
2026-06-111
PoC1
2026-07-111
Active Exploitation1
2026-07-131
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    Progress ShareFile has a pre-auth RCE chain affecting customer-managed deployments. CVE-2026-2699 (auth bypass) + CVE-2026-2701 (RCE) let attackers skip login, access admin endpoints, and upload web shells. ~30k internet-facing instances affected. Fixed in 5.12.4. 🔗 Exploit chain and impact → https://thehackernews.com/2026/04/threatsday-bulletin-pre-auth-chains.html#pre-auth-rce-chain-exposed

    Post summary

    Progress ShareFile’s auth bypass (CVE‑2026‑2699) and RCE (CVE‑2026‑2701) allow attackers to upload shells to ~30k internet‑facing instances; patch 5.12.4 is available.

    4291862711.9K
    1.6M followersView on X
  • Dhiyaneshwaran@DhiyaneshDK
    PoC

    🚨 CVE-2026-2699 - Progress ShareFile Storage Zone Controller - Authentication Bypass 🔍 Nuclei Template: https://cloud.projectdiscovery.io/library/CVE-2026-2699 📑 Reference: https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ #bugbounty #infosec #nuclei #hackwithautomation https://t.co/mOhMbUePfJ

    Post summary

    The tweet announces CVE‑2026‑2699, an authentication bypass in Progress ShareFile Storage Zone Controller, and provides a Nuclei detection template plus a reference article, but offers no evidence of active exploitation, patching, or exploitation code.

    019080345.2K
    4.5K followersView on X
  • Densel@luckyhacker43
    PoC

    New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In ⚡️ 🔗 https://watchtowr.com/resources/progress-sharefile-storage-zone-controller-pre-auth-rce-cve-2026-2699-cve-2026-2701/ 🔗 https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ 🔗 https://cybersecuritynews.com/progress-sharefile-vulnerability/ Join team 👉https://t.me/luckyhacker43 https://t.co/R7dIqxnpED

    Post summary

    The post promotes resources that detail proofs of concept for CVE-2026-2699 and CVE-2026-2701 in Progress ShareFile, showcasing pre-authentication remote code execution exploits, with no evidence presented of active exploitation or patches.

    04025101.1K
    2.8K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Patch

    We added Progress ShareFile fingerprinting to our scans & reports with 784 unique IPs seen exposed on 2026-04-02. @watchtowrcyber recently disclosed details behind an RCE CVE-2026-2699 & CVE-2026-2701 exploit chain affecting ShareFile. Make sure to apply the latest patch! https://t.co/aVvl83pzt4

    Post summary

    The tweet announces that two RCE CVEs (CVE‑2026‑2699 and CVE‑2026‑2701) affect ShareFile and urges users to apply the latest patch.

    1811335.7K
    21.8K followersView on X
  • Team D4rkn3ttz@Team_D4rkn3ttz
    Active Exploitation

    IR/CERT Morning Brief Today’s priorities: alleged mass exploitation of CVE-2025-55182 affecting exposed Next.js hosts, a pre-auth ShareFile RCE chain (CVE-2026-2699 / CVE-2026-2701), and malware delivery following the Claude Code source leak. Also watching Iran-linked cloud password spraying. Bottom line: patch exposed web/file-sharing assets, protect dev/CI credentials, and tighten cloud auth monitoring. #cybersecurity #threatintel #IR #CERT

    Post summary

    The brief highlights alleged mass exploitation of CVE-2025-55182 on exposed Next.js hosts and a pre‑auth ShareFile RCE chain, urging patches and tighter cloud authentication monitoring.

    70030566
    320 followersView on X
  • Nicolas Krassas@Dinosn
    General

    You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The text points to a blog post covering two pre‑authentication RCE chain vulnerabilities (CVE‑2026‑2699 & CVE‑2026‑2701) but does not provide PoC, exploit, patch, or active exploitation details.

    000531.6K
    157.2K followersView on X
  • Florian Hansemann@CyberWarship
    PoC

    ''You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)'' #infosec #pentest #redteam #blueteam https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The post announces two Progress ShareFile pre-auth RCE vulnerabilities (CVE-2026-2699 & CVE-2026-2701), outlining a chain of exploits and providing technical details, but does not address active exploitation, patches, or debunking.

    000331.3K
    88.4K followersView on X
  • /r/netsec@_r_netsec
    PoC

    You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    WatchTowr Labs releases a proof‑of‑concept for a pre‑authenticated RCE chain in Progress ShareFile (CVE‑2026‑2699 & CVE‑2026‑2701), detailing the vulnerability and its exploitation steps.

    00041661
    33.3K followersView on X
  • ET Labs@ET_Labs
    General

    18 new OPEN, 67 new PRO (18 + 49) AuraC2, Lumma Stealer, NetSupport RAT, Progress ShareFile (CVE-2026-2699, CVE-2026-2701), XWorm, ZPHP Thanks @whoamix302 https://community.emergingthreats.net/t/ruleset-update-summary-2026-04-07-v11166/3257

    Post summary

    The post enumerates new rule entries and lists two CVE identifiers but gives no further technical or actionable details about those vulnerabilities.

    02011372
    5.7K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Patch

    Top affected: US, Germany Patch: https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26 Note: we are just sharing exposed population, there is no vulnerability assessment Background: https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ CVE-2026-2699 NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-2699 CVE-2026-2701 NVD entry: https://nvd.nist.gov/vuln/detail/CVE-2026-2701

    Post summary

    The post announces the availability of a patch for ShareFile CVEs 2026‑2699 and 2026‑2701, referencing background information but not providing exploit details.

    01021636
    21.8K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    Progress ShareFileで認証バイパス+RCEのexploitチェーン😱 You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/

    Post summary

    The post announces a new pre‑auth RCE chain for Progress ShareFile (CVE‑2026‑2699 & CVE‑2026‑2701), linking to an article that likely contains PoC details, but it does not mention active exploitation, a patch, or a false‑positive claim.

    110201.3K
    6.9K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Two Critical Remote Code Execution Vulnerabilities in #ShareFile Storage Zones Controller. CVE-2026-2699 CVE-2026-2701 CVSS: 9.8 CVSS 9.1. These two vulnerabilities chained together can lead to a full-system compromise. #RCE! #Patch #Patch #Patch

    Post summary

    Two critical RCE vulnerabilities (CVE-2026-2699 & CVE-2026-2701) in ShareFile Storage Zones Controller have been disclosed, with CVSS scores of 9.8 and 9.1; the vulnerabilities can be chained for full‑system compromise, prompting a patch reminder.

    02010351
    7.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Progress ShareFile Storage Zone Controller hit with critical pre-auth RCE chain. CVE-2026-2699 authentication bypass combined with CVE-2026-2701 RCE enables complete compromise of 30,000+ internet-facing instances. Technical breakdown: • CVE-2026-2699: Execution After Redirect (CWE-698) in /ConfigService/Admin.aspx - Response.Redirect() called with 'false' parameter allows code execution to continue after redirect • CVE-2026-2701: File upload path manipulation + ZIP extraction abuse enables webshell deployment to webroot directory • Attack chain: Bypass auth → modify Zone configuration → change storage path to webroot → upload ZIP with ASPX webshell → extract via unzip=true parameter • Affects StorageCenter 5.x branch (http://ASP.NET), patched in version 5.12.4 released March 10, 2026 DFIR artifacts: • HTTP 302 responses with >10,000 character body from /ConfigService/Admin.aspx • Modifications to Zone configuration files and storage repository settings • Unusual ZIP uploads to /upload.aspx with unzip=true parameter • ASPX files extracted to webroot directories (C:\inetpub\wwwroot\ShareFile\) Hunt for HTTP requests to /ConfigService/Admin.aspx returning 302 with large response bodies, and monitor for unexpected file uploads to administrative endpoints. #DFIR_Radar

    Post summary

    The post outlines a pre‑auth RCE chain involving CVE‑2026‑2699 and CVE‑2026‑2701 that has reportedly compromised over 30,000 ShareFile instances, provides technical breakdowns, and announces a patch released on March 10 2026.

    10011350
    1.7K followersView on X
  • Arctic Wolf@AWNetworks
    Patch

    Progress ShareFile has released fixes for two critical severity vulnerabilities in Progress ShareFile Storage Zones Controller (SZC) 5.x, tracked as CVE-2026-2699 and CVE-2026-2701. Learn more in our latest security bulletin: https://arcticwolf.com/resources/blog/cve-2026-2699-cve-2026-2701/?utm_source=Twitter&utm_medium=social&utm_campaign=ADV%20FY26%20Social%20Twitter

    Post summary

    Progress ShareFile has released fixes for CVE-2026-2699 and CVE-2026-2701, as detailed in their security bulletin.

    02000234
    4.5K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Progress ShareFile Storage Zone Controller pre-auth Authentication Bypass and Chained RCE (CVE-2026-2699, CVE-2026-2701) 📅 **Timeline:** Disclosure: 2026-04-02 · Patch: 2026-03-10 🆔 **CVE-2026-2699** | 📊 CVSS: 9.8 (CRITICAL 🔴) 🆔 **CVE-2026-2701** | 📊 CVSS: 9.1 (CRITICAL 🔴) 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** Progress ShareFile Storage Zone Controller (SZC) branch 5.x, Versions prior to 5.12.4 (<5.12.4) 🔧 **Fixed Versions:** Progress ShareFile 5.12.4 🫨 **Attack Vectors:** - Pre-auth HTTP redirect handling / authentication bypass to access admin UI - File upload and archive extraction to place ASPX webshells in webroot - Abuse of storage zone passphrase/secrets to decrypt/extract HMAC-capable secrets - Chained exploitation (auth bypass + file upload) to achieve unauthenticated RCE 📝 **Summary:** A pre-auth auth-bypass in SZC (CVE-2026-2699) combined with a file-upload/archive-extraction flaw (CVE-2026-2701) allows attackers to plant ASPX webshells and retrieve secrets. When chained this results in unauthenticated RCE, potential full server compromise and large-scale data exfiltration on exposed SZC instances. 📈 **Impact Scope:** Remote code execution, potential full server compromise and large-scale data exfiltration for exposed Customer-managed Storage Zone Controller instances (SZC branch 5.x prior to 5.12.4). 🛡️ **Recommended Actions:** - Upgrade SZC to Progress ShareFile 5.12.4 immediately - Isolate/restrict SZC admin interfaces to management networks or VPN; remove public exposure - Rotate storage zone passphrases, keys and any HMAC secrets after patching - Scan for ASPX webshells, unexpected uploaded/extracted files and review auth/redirect logs - Deploy WAF rules, stricter upload validation and segment SZC hosts; monitor for data exfiltration 🪢 **Related Resources:** - http://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ - https://docs.sharefile.com/en-us/storage-zones-controller/5-0/security-vulnerability-feb26 🏷 **Tags:** #Cybersecurity #ProgressShareFile #RCE

    Post summary

    The alert reports two critical CVEs (CVE‑2026‑2699 and CVE‑2026‑2701) in Progress ShareFile Storage Zone Controller with a PoC, provides detailed technical information, and recommends immediate patching to mitigate potential remote code execution and data exfiltration.

    0001194
    277 followersView on X
  • Syed Aquib@syedaquib77
    PoC

    ⚠️ **Vulnerability Alert:** Progress ShareFile Storage Zones Controller pre-auth RCE chain 📅 **Timeline:** Disclosure: 2026-04-02 · Patch: 2026-03-10 🆔 **CVE-2026-2699** | 📊 CVSS: 9.8 (CRITICAL 🔴) 🆔 **CVE-2026-2701** | 📊 CVSS: 9.1 (CRITICAL 🔴) 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** ShareFile SZC 5.x (prior to 5.12.4) 🔧 **Fixed Versions:** ShareFile 5.12.4 🫨 **Attack Vectors:** - Authentication bypass via improper handling of HTTP redirects - Abuse of file upload/extraction to place ASPX webshells in webroot - Passphrase/HMAC manipulation and secret extraction 📝 **Summary:** Two chained critical flaws allow pre-auth bypass of admin controls and unsafe file handling that together enable unauthenticated RCE and ASPX webshell deployment. Impacted, network-reachable customer-managed SZC 5.x instances risk data exfiltration, persistence, and full server compromise. 📈 **Impact Scope:** Affected customer-managed ShareFile SZC 5.x instances reachable on the network may allow unauthenticated RCE leading to webshell deployment, data exfiltration, persistence, and full server compromise. Enables ransomware and data-theft attacks against impacted organizations. 🛡️ **Recommended Actions:** - Apply patch: upgrade to ShareFile 5.12.4 immediately - If unable to patch, block external access to SZC admin interfaces and file upload endpoints - Rotate storage zone passphrases and rekey HMAC/secret material - Scan webroots for ASPX webshells, review logs for unusual uploads/admin changes, and restore from known-good backups if compromised 🪢 **Related Resources:** - https://www.youtube.com/watch?v=KsZ6tROaVOQ - https://en.wikipedia.org/wiki/2 🏷 **Tags:** #Cybersecurity #ShareFile #RCE

    Post summary

    The post announces two critical ShareFile CVEs with a proof‑of‑concept highlighted, urging immediate patching or mitigations to prevent unauthenticated RCE and webshell deployment.

    00011131
    277 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Progress ShareFile の脆弱性 CVE-2026-2699/2701 が FIX:連鎖によるリモート制御の奪取 https://iototsecnews.jp/2026/04/03/new-progress-sharefile-flaws-expose-servers-to-unauthorized-remote-takeover/ この問題の原因は、 プログラムの実装における小さな見落としが積み重なったことにあります。 CVE-2026-2699 では、リダイレクト命令の後に処理を終了させなかったために、本来は隠されるべき管理画面が読み込まれてしまいました。また、CVE-2026-2701 では、ファイルの保存先を指定する際に、その場所が Web 公開領域であるかどうかのチェックが漏れていました。 これらの脆弱性が組み合わさることで、 外部から自由に Web シェルを配置できる状態になってしまいました。ご利用のチームは、ご注意ください。 #CVE20262699 #CVE20262701 #Progress #ShareFile #Vulnerability

    Post summary

    The post discloses two new CVE vulnerabilities in Progress ShareFile that enable arbitrary web shell deployment; it offers technical details but no PoC, exploit code, active exploitation reports, or specific patch information.

    01000168
    483 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical CVE-2026-2699 and CVE-2026-2701 in Progress ShareFile Storage Zones Controller enable unauthenticated RCE and file exfiltration on 30,000 internet-exposed instances. https://threatcluster.io/cluster/critical-vulnerabilities-in-progress-sharefile-enable-unauth-6f0c242f

    Post summary

    The post announces two critical vulnerabilities (CVE-2026-2699 and CVE-2026-2701) that allow unauthenticated remote code execution and file exfiltration on Progress ShareFile Storage Zones Controller, potentially impacting up to 30,000 internet‑exposed instances.

    0000172
    129 followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 &amp; CVE-2026-2701) - watchTowr Labs https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/ https://t.co/Rw6wU6NxEK

    Post summary

    The post announces the discovery of two Progress ShareFile pre‑authentication remote code execution vulnerabilities (CVE‑2026‑2699, CVE‑2026‑2701) and outlines the exploitation chain, but offers no PoC, exploit code, or patch information.

    00010155
    905 followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    🚨 Progress tells ShareFile customers to shut down Storage Zone Controllers NOW amid an active external threat 🔹 ShareFile access via controllers temporarily disabled during investigation 🔹 Attackers may be chaining CVE-2026-2699 & CVE-2026-2701 → unauthenticated RCE 🔹 No evidence of data compromise — so far ⚠️ Decommission, patch & monitor logs

    Post summary

    Progress warns ShareFile customers of an active threat exploiting CVE-2026-2699 and CVE-2026-2701 for unauthenticated RCE, urging controller shutdown and patching while the investigation continues.

    0000082
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogresssharefile_storage_zones_controller---

Explore more