Security Vulnerability Fix For ShareFile Storage Zones Controller 5.x (February 2026)
Overview
Critical Security – February 2026 – CVE-2026-2699 and CVE-2026-2701
The Progress ShareFile team recently confirmed critical security vulnerabilities in ShareFile Storage Zones Controller v5 version deployments for customer managed zones. Currently, we have not received any reports that these vulnerabilities have been exploited.
These vulnerabilities allow an unauthenticated remote attacker to access on-prem storage zones controller’s configuration pages, potentially leading to changes in system configuration and remote code execution.
Issues
CVE-2026-2699 - Execution After Redirect
CVE-2026-2701 - Remote Code Execution
Solution
We have addressed the vulnerabilities in v5 latest version. We strongly recommend customers upgrading to latest v5 patch version v5.12.4 or customers can upgrade to any v6 version as V6 versions are not impacted by these vulnerabilities.
| Fixed Version | Documentation |
|---|---|
| v5.12.4 | v5 upgrade |
| Any v6 version | v6 upgrade |
If you have any questions or concerns related to this issue, please login to open a new Technical Support. Technical Support is available to ShareFile Storage Zone Controller v5.x customers under warranty and active maintenance.
If your version is no longer supported, you should upgrade to a supported and fixed version.