Storage zones controller

Security Vulnerability Fix For ShareFile Storage Zones Controller 5.x (February 2026)

Overview

Critical Security – February 2026 – CVE-2026-2699 and CVE-2026-2701

The Progress ShareFile team recently confirmed critical security vulnerabilities in ShareFile Storage Zones Controller v5 version deployments for customer managed zones. Currently, we have not received any reports that these vulnerabilities have been exploited.

These vulnerabilities allow an unauthenticated remote attacker to access on-prem storage zones controller’s configuration pages, potentially leading to changes in system configuration and remote code execution.

Issues

CVE-2026-2699 - Execution After Redirect

CVE-2026-2701 - Remote Code Execution

Solution

We have addressed the vulnerabilities in v5 latest version. We strongly recommend customers upgrading to latest v5 patch version v5.12.4 or customers can upgrade to any v6 version as V6 versions are not impacted by these vulnerabilities. 

Fixed Version Documentation
v5.12.4  v5 upgrade
Any v6 version v6 upgrade

If you have any questions or concerns related to this issue, please login to open a new Technical Support. Technical Support is available to ShareFile Storage Zone Controller v5.x customers under warranty and active maintenance.

If your version is no longer supported, you should upgrade to a supported and fixed version.

Security Vulnerability Fix For ShareFile Storage Zones Controller 5.x (February 2026)