The National Cyber Security Centre of Ireland has renewed attention on two critical vulnerabilities in Progress ShareFile Storage Zones Controller, a component used by organisations that operate customer-managed storage zones for file sharing and collaboration.
CVE-2026-2699 and CVE-2026-2701 affect version 5 deployments before 5.12.4. Individually, the flaws are serious; together, they create a path from unauthenticated access to restricted management functions to remote code execution on an on-premises controller. For enterprises using Storage Zones Controller to retain closer control of where sensitive documents reside, the issue is not confined to a routine software update. It is a test of whether systems that bridge external file exchange and internal data stores are properly inventoried, patched and monitored.
A chain that changes the risk profile
CVE-2026-2699 has a CVSS score of 9.8. It concerns an execution-after-redirect condition that can allow an unauthenticated attacker to reach restricted configuration pages on a customer-managed Storage Zones Controller. Access to those pages can permit configuration changes and create the conditions for further compromise.
CVE-2026-2701, rated 9.1, is a remote-code-execution vulnerability involving the upload and execution of a malicious file. On its own, the flaw is described as requiring an authenticated user. However, security advisories have warned that pairing it with the access-control weakness in CVE-2026-2699 can remove that practical barrier. An external attacker could first gain access to administrative functions and then abuse file-upload and extraction behaviour to place server-side code in the application web root.
That sequence makes the vulnerability pair more consequential than a typical authenticated upload flaw. A compromised controller may provide an attacker with an execution point in a Windows-based environment that is designed to move, store or broker access to business files. The ultimate business impact depends on the controller’s permissions, network segmentation, connected file shares and monitoring controls, but the potential consequences include service disruption, data access and a foothold for broader intrusion.
The affected estate is narrower than ShareFile as a whole
The vulnerabilities apply to customer-managed ShareFile Storage Zones Controller 5.x installations rather than to every ShareFile deployment. Progress states that version 5.12.4 addresses both issues, while version 6 is not affected by these two CVEs.
That distinction matters operationally. Security teams should not assume that a cloud-service inventory or a general ShareFile subscription review will reveal vulnerable systems. The relevant assets may be Windows servers owned by infrastructure teams, hosted in a perimeter network, managed by a regional business unit or maintained by a third-party provider. Older controllers can also persist after application migrations because they remain tied to file repositories, integrations or longstanding customer workflows.
The practical first step is therefore asset identification. Organisations should determine whether they run customer-managed storage zones, identify every associated controller and confirm the installed version directly on each host. They should also establish whether any controller is reachable from the public internet, whether it is protected by a reverse proxy or web application firewall, and which internal network shares, identity services and service accounts it can access.
Public exploit material raises the urgency
The pair was publicly documented with proof-of-concept material after disclosure. That does not by itself establish that the vulnerabilities are being used in attacks, but it reduces the effort required for opportunistic scanning and exploitation by other actors. NHS England’s cyber alert assessed exploitation as highly likely, reflecting the combination of high severity, a public-facing attack surface and publicly available demonstration material.
Progress said in its vulnerability notice that it had not received reports of exploitation when the notice was issued. Ireland’s July advisory also listed neither CVE as a known exploited vulnerability in the US government’s catalogue at the time of publication. Those are useful indicators, but they should not be read as evidence that unpatched controllers are safe. Known-exploitation catalogues are intentionally selective and tend to lag early attack activity; absence from a list does not substitute for remediation.
July disruption should not be confused with these CVEs
The renewed advisory also arrives shortly after a separate ShareFile Storage Zones Controller security incident in July. Progress temporarily took affected customer access offline while it investigated a credible external threat, then restored service after providing recovery instructions. Reporting on that event identified a different high-severity path-traversal vulnerability affecting Storage Zones Controller 5.x and 6.x.
The two April CVEs and the July path-traversal issue should be handled as separate security events. CVE-2026-2699 and CVE-2026-2701 are fixed by upgrading vulnerable 5.x installations to at least version 5.12.4 or by moving to version 6. The later issue has its own remediation path and affects a broader version range. Teams should check current vendor guidance for both rather than regard the July service restoration as confirmation that all historic ShareFile controller weaknesses have been addressed.
This distinction is especially important for change-management records. A server patched for the July issue may still need verification that the earlier fixed release level was reached, while a controller upgraded to 5.12.4 for the two CVEs may require a later update for the path-traversal vulnerability.
What enterprise defenders should do now
For organisations that identify a vulnerable 5.x controller, the primary action is to upgrade to version 5.12.4 or later after appropriate testing, or migrate to a supported version 6 release where that is the chosen operating model. Unsupported deployments should be treated as a replacement or upgrade priority, not as an exception to be managed indefinitely.
Patching should be accompanied by targeted validation. Administrators should review internet exposure, configuration changes, local administrator and service-account permissions, web-server logs, authentication logs and file-system activity on the controller. Particular attention should go to unexpected administrative access, new or altered application files, suspicious archive uploads, unusual child processes launched by web services and outbound connections from the host.
Network design also influences the consequences of a compromise. Storage controllers should be segmented from high-value internal systems and granted only the access required to perform their file-transfer role. Administrative interfaces should be restricted to trusted management networks where possible, and endpoint detection, log retention and alerting should cover the controller itself rather than only the storage it serves.
The wider lesson is that self-managed file-transfer components demand the same discipline as remote-access gateways and web-facing identity systems. Their function is to make sensitive information available across organisational boundaries; that utility also makes them an attractive target. In this case, the available fixes are clear. The remaining challenge for enterprises is discovering every exposed controller and proving that each one has been brought to a supported, remediated state.
Sources
- Critical Vulnerabilities in Progress ShareFile Storage Zones Controller — National Cyber Security Centre Ireland
- Security Vulnerability Fix For ShareFile Storage Zones Controller 5.x — Progress ShareFile Documentation
- Progress Releases Security Updates for ShareFile Storage Zones Controller — NHS England Digital
- Multiple Vulnerabilities in Progress ShareFile Could Allow for Remote Code Execution — Center for Internet Security
- ShareFile Status Page — ShareFile



