Progress Software Corporation

Progress Software traced its July 2026 ShareFile Storage Zone Controller shutdown to a high-severity path traversal zero-day affecting all 5.x and 6.x versions and initially released versions 5.12.5 and 6.0.2. The containment action disrupted access to customer-managed files until July 14, but Progress said it had no indication of unauthorized access to customer accounts or data and had identified no active threat.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
A specific application or software platform became unavailable or unusable.
Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that Progress Software’s response to a high-severity ShareFile Storage Zone Controller vulnerability caused a material access disruption for affected customers from July 10 to July 14, 2026. Progress temporarily disabled affected ShareFile accounts and told customers to shut down controller servers while internal and external cybersecurity specialists investigated.
On July 14, BleepingComputer reported that Progress had identified a path traversal vulnerability affecting all 5.x and 6.x Storage Zone Controller versions. Progress said an authenticated administrative user could read arbitrary files accessible to the application’s service account, write threat-actor-controlled content to arbitrary directories or enumerate the server filesystem. The company initially released versions 5.12.5 and 6.0.2 and said controllers could return to service after customers installed the update.
The finding explains the emergency response but does not establish successful exploitation. Progress said it acted after receiving credible information about a potential threat, patched the vulnerability before it was publicly known, found no indication of unauthorized access to any customer account or data, and identified no active threat. DysruptionHub therefore retains an unknown cyber mechanism rather than classifying the event as confirmed vulnerability exploitation.
The response interrupted access for customers using privately managed Storage Zone Controllers. These customer-managed Windows servers keep files in customer environments while relying on ShareFile’s cloud platform for authentication, permissions, auditing and collaboration. Disabling affected accounts and shutting down controllers therefore impaired the online service, application and access to customer-managed files.
The operational burden extended to downstream organizations that depended on ShareFile for file storage and collaboration. Progress restored cloud access by July 12, but controllers remained offline until patches and recovery instructions were issued July 14. The public record does not identify the number, sectors or geographic distribution of affected customers or establish when every customer completed its own upgrade and restart.
The disruption made data unavailable to authorized users, supporting an availability impact. It does not establish unauthorized data access, theft, exposure, alteration, corruption or destruction.
Progress directly notified affected customers of the credible external threat and required shutdown actions, then provided public status information. Its July 14 customer update disclosed the vulnerability class, affected major versions, potential authenticated-administrator capabilities and initial fixed versions. Progress reserved a CVE but said publication would be delayed to give customers time to patch; no public CVE for this July flaw was found by the research cutoff.
The newly disclosed issue is distinct from CVE-2026-2699 and CVE-2026-2701, earlier ShareFile Storage Zone Controller 5.x vulnerabilities published in April. The July path traversal affected both 5.x and 6.x branches, and the reviewed evidence does not link the February flaws to this shutdown.
The ShareFile status page marked the incident resolved July 14 at 11:06 EDT, said Storage Zone Controller customer access was being restored and said recovery instructions had been provided directly to account owners. On July 26 the page showed all systems operational and listed no additional incidents from July 15 through July 25.
Resolved status means Progress restored platform access and enabled customers to recover by patching and restarting their controllers. It does not establish that every customer completed remediation at the same time. An unverified administrator report suggested a later build may have appeared in the customer download area, but no authoritative public source confirmed a superseding version, so the assessment records 5.12.5 and 6.0.2 only as the initial recovery patches.
Confidence is high in the vulnerability finding, affected version families, containment-driven outage and July 14 recovery because Progress supplied those details and the official status page documented the disruption and resolution. Confidence remains low regarding actual exploitation, unauthorized access and attacker activity because Progress said it found no customer compromise or active threat and no reviewed source provided contrary evidence.
The data-impact assessment is limited to availability: authorized users could not access customer-managed files during the shutdown. Confidentiality and integrity impacts remain unestablished. Ransomware is assessed as not involved, threat-actor attribution remains unresolved and no extortion indicator was identified.
The public record does not establish who supplied the warning, whether an attacker attempted or successfully exploited the flaw, the affected endpoint or request path, how administrative authentication could be obtained, the number of exposed or affected controllers, or whether any individual customer later found compromise. It also does not identify a CVE for the July flaw, publish indicators of compromise or provide a public forensic report.
Further vendor disclosure is needed to determine whether the initial 5.12.5 and 6.0.2 releases were superseded, whether additional mitigations are required and whether later customer investigations identified unauthorized access. A later CVE, security advisory, customer breach notice or regulator filing could materially change the assessment.

Progress said it identified a credible external security threat targeting ShareFile Storage Zone Controllers, disabled access for affected accounts and instructed customers to shut down controller servers. Cloud access was restored by July 12, but controllers remained offline; Progress said it had no evidence of unauthorized access to customer accounts or data and had not identified an active threat.
Progress said it identified a high-severity path traversal vulnerability affecting all ShareFile Storage Zone Controller 5.x and 6.x versions and initially released versions 5.12.5 and 6.0.2. The company said an authenticated administrator could read service-account-accessible files, write controlled content to arbitrary directories or enumerate the filesystem, but it had no indication of unauthorized customer account or data access and no active threat.
The ShareFile status page marked the Storage Zone Controller incident resolved July 14 at 11:06 EDT, said customer access was being restored and said recovery instructions had been provided directly to account owners. On July 26 it showed all systems operational and no additional incidents from July 15 through July 25.
Signed-in members can report an error, update, or missing source.