Skip to content

Progress ShareFile zero-day disrupts storage access

Summary

Progress Software Corporation logo

Progress Software traced its July 2026 ShareFile Storage Zone Controller shutdown to a high-severity path traversal zero-day affecting all 5.x and 6.x versions and initially released versions 5.12.5 and 6.0.2. The containment action disrupted access to customer-managed files until July 14, but Progress said it had no indication of unauthorized access to customer accounts or data and had identified no active threat.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Cloud service disruption

    Cloud-hosted infrastructure, software, storage, identity, or platform services were unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Progress Software’s response to a high-severity ShareFile Storage Zone Controller vulnerability caused a material access disruption for affected customers from July 10 to July 14, 2026. Progress temporarily disabled affected ShareFile accounts and told customers to shut down controller servers while internal and external cybersecurity specialists investigated.

On July 14, BleepingComputer reported that Progress had identified a path traversal vulnerability affecting all 5.x and 6.x Storage Zone Controller versions. Progress said an authenticated administrative user could read arbitrary files accessible to the application’s service account, write threat-actor-controlled content to arbitrary directories or enumerate the server filesystem. The company initially released versions 5.12.5 and 6.0.2 and said controllers could return to service after customers installed the update.

The finding explains the emergency response but does not establish successful exploitation. Progress said it acted after receiving credible information about a potential threat, patched the vulnerability before it was publicly known, found no indication of unauthorized access to any customer account or data, and identified no active threat. DysruptionHub therefore retains an unknown cyber mechanism rather than classifying the event as confirmed vulnerability exploitation.

Operational significance

The response interrupted access for customers using privately managed Storage Zone Controllers. These customer-managed Windows servers keep files in customer environments while relying on ShareFile’s cloud platform for authentication, permissions, auditing and collaboration. Disabling affected accounts and shutting down controllers therefore impaired the online service, application and access to customer-managed files.

The operational burden extended to downstream organizations that depended on ShareFile for file storage and collaboration. Progress restored cloud access by July 12, but controllers remained offline until patches and recovery instructions were issued July 14. The public record does not identify the number, sectors or geographic distribution of affected customers or establish when every customer completed its own upgrade and restart.

The disruption made data unavailable to authorized users, supporting an availability impact. It does not establish unauthorized data access, theft, exposure, alteration, corruption or destruction.

Disclosure posture

Progress directly notified affected customers of the credible external threat and required shutdown actions, then provided public status information. Its July 14 customer update disclosed the vulnerability class, affected major versions, potential authenticated-administrator capabilities and initial fixed versions. Progress reserved a CVE but said publication would be delayed to give customers time to patch; no public CVE for this July flaw was found by the research cutoff.

The newly disclosed issue is distinct from CVE-2026-2699 and CVE-2026-2701, earlier ShareFile Storage Zone Controller 5.x vulnerabilities published in April. The July path traversal affected both 5.x and 6.x branches, and the reviewed evidence does not link the February flaws to this shutdown.

Current status

The ShareFile status page marked the incident resolved July 14 at 11:06 EDT, said Storage Zone Controller customer access was being restored and said recovery instructions had been provided directly to account owners. On July 26 the page showed all systems operational and listed no additional incidents from July 15 through July 25.

Resolved status means Progress restored platform access and enabled customers to recover by patching and restarting their controllers. It does not establish that every customer completed remediation at the same time. An unverified administrator report suggested a later build may have appeared in the customer download area, but no authoritative public source confirmed a superseding version, so the assessment records 5.12.5 and 6.0.2 only as the initial recovery patches.

Confidence and uncertainty

Confidence is high in the vulnerability finding, affected version families, containment-driven outage and July 14 recovery because Progress supplied those details and the official status page documented the disruption and resolution. Confidence remains low regarding actual exploitation, unauthorized access and attacker activity because Progress said it found no customer compromise or active threat and no reviewed source provided contrary evidence.

The data-impact assessment is limited to availability: authorized users could not access customer-managed files during the shutdown. Confidentiality and integrity impacts remain unestablished. Ransomware is assessed as not involved, threat-actor attribution remains unresolved and no extortion indicator was identified.

Analytic gaps

The public record does not establish who supplied the warning, whether an attacker attempted or successfully exploited the flaw, the affected endpoint or request path, how administrative authentication could be obtained, the number of exposed or affected controllers, or whether any individual customer later found compromise. It also does not identify a CVE for the July flaw, publish indicators of compromise or provide a public forensic report.

Further vendor disclosure is needed to determine whether the initial 5.12.5 and 6.0.2 releases were superseded, whether additional mitigations are required and whether later customer investigations identified unauthorized access. A later CVE, security advisory, customer breach notice or regulator filing could materially change the assessment.

Organizations involved

Impacted location

Sources

Massachusetts-based Progress keeps ShareFile servers offline during security investigation

Progress said it identified a credible external security threat targeting ShareFile Storage Zone Controllers, disabled access for affected accounts and instructed customers to shut down controller servers. Cloud access was restored by July 12, but controllers remained offline; Progress said it had no evidence of unauthorized access to customer accounts or data and had not identified an active threat.

Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown

Progress said it identified a high-severity path traversal vulnerability affecting all ShareFile Storage Zone Controller 5.x and 6.x versions and initially released versions 5.12.5 and 6.0.2. The company said an authenticated administrator could read service-account-accessible files, write controlled content to arbitrary directories or enumerate the filesystem, but it had no indication of unauthorized customer account or data access and no active threat.

ShareFile Status Page

The ShareFile status page marked the Storage Zone Controller incident resolved July 14 at 11:06 EDT, said customer access was being restored and said recovery instructions had been provided directly to account owners. On July 26 it showed all systems operational and no additional incidents from July 15 through July 25.

See something that needs correction?

Signed-in members can report an error, update, or missing source.