Vulnerability intelligence
CVE-2026-2699
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
60%
Riskier than 99% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
4 articles across 3 outlets · first covered Apr 2, 2026 · latest Jul 13, 2026
Coverage timeline
-
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concernswww.securityweek.com · Jul 13, 2026
-
Critical ShareFile Flaws Lead to Unauthenticated RCEwww.securityweek.com · Apr 3, 2026
-
Preauth RCE chain targets Progress ShareFile Storage Zones 5.xsocradar.io · Apr 3, 2026
-
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Storiesthehackernews.com · Apr 2, 2026