CVE-2026-15724: Progress ShareFile Storage Zones Controller
High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.
Affected products
- Progress ShareFile Storage Zones Controller: before 5.12.6 (fixed in 5.12.6); from 6.0, before 6.0.3 (fixed in 6.0.3)
Published 2026-07-21. Last modified 2026-09-03.