CVE-2026-2699: Progress ShareFile Storage Zones Controller
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Affected products
- Progress ShareFile Storage Zones Controller: from 5.0.0, before 5.12.4 (fixed in 5.12.4)
Published 2026-04-02. Last modified 2026-06-17.