{"id":11876,"date":"2026-04-05T10:03:39","date_gmt":"2026-04-05T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/05\/new-progress-sharefile-bugs-let-attackers-take-over-servers-without-logging-in\/"},"modified":"2026-04-05T10:03:39","modified_gmt":"2026-04-05T10:03:39","slug":"new-progress-sharefile-bugs-let-attackers-take-over-servers-without-logging-in","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/05\/new-progress-sharefile-bugs-let-attackers-take-over-servers-without-logging-in\/","title":{"rendered":"New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In"},"content":{"rendered":"<p>    New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A dangerous attack chain in Progress ShareFile that can allow attackers to take over exposed on-premises servers without first logging in.<\/p>\n<p>The issues affect customer-managed ShareFile Storage Zones Controller 5.x deployments, and Progress says customers should upgrade to version 5.12.4 or move to any 6.x release, which is not impacted.<\/p>\n<p>According to Progress and WatchTower, the first bug is an authentication bypass that exposes restricted configuration pages, while the second <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">enables remote code execution via\u00a0<a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-leverage-windows-run-dialog-box\/\" target=\"_blank\" rel=\"noopener\">malicious file uploads<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/new-clickfix-attack-leverage-windows-run-dialog-box\/\" target=\"_blank\" rel=\"noreferrer noopener\"> and execution.<\/a><\/p>\n<p>RunZero lists both flaws CVE-2026-2699 (CVSS 9.8) and CVE-2026-2701 (CVSS 9.1) as critical.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-progress-sharefile-vulnerability\">\n<strong>Progress ShareFile<\/strong> <strong>Vulnerability<\/strong><br \/>\n<\/h2>\n<p>The attack targets the ShareFile Storage Zones Controller. This on-premises component lets organizations store files in their own infrastructure while still using ShareFile\u2019s cloud-based management interface.<\/p>\n<p>That design is often used by enterprises with compliance, sovereignty, or internal security requirements, and watchTower estimated that around 30,000 Storage Zone Controller instances are internet-facing.<\/p>\n<p>Because these servers sit at the edge of file-sharing workflows, they are especially attractive targets for ransomware groups and other threat actors.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYnrMVclLovcdERbj2_k2xQ0lkxAuCnqbMXy-37RQShJt6ytamR00jvsPmeRF4vscVbHMH-MabdQDJZ7CK4I9I-s04bDKSTGzFLpj1ZWakvXDGshXXmN4YaTlqo06b_3f94n52A6rbV3B4q426SHwU9t1z2QOCKPLs1CUdRyQgwbBdqBr7yXa6sCQZ5kg\/s1600\/Screenshot%25202026-04-03%2520192221%2520%25281%2529.webp?ssl=1\" alt=\"uploaded file with no extension and randomized name(Source: WatchTowr)\"><figcaption class=\"wp-element-caption\"><em>uploaded file with no extension and randomized name(Source: WatchTowr)<\/em><\/figcaption><\/figure>\n<\/div>\n<p>WatchTowr found that the authentication bypass is caused by an Execution After Redirect condition on the Admin.aspx configuration page.<\/p>\n<p>In simple terms, the application sends an HTTP 302 redirect to the login page. However, the page logic continues running, which can <a href=\"https:\/\/cybersecuritynews.com\/servicenow-vulnerability\/\">expose admin functionality to an unauthenticated user.<\/a><\/p>\n<p>The researchers said this behavior is tied to the way the application uses a redirect function that does not properly stop execution.<\/p>\n<p>After gaining access to the admin interface, an attacker can modify important zone settings, including storage paths and passphrase-related values.<\/p>\n<p>That access becomes more serious because the second bug allows a malicious archive to be uploaded and extracted into a server-controlled path, <a href=\"https:\/\/cybersecuritynews.com\/livewire-filemanager-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">including a web-accessible directory.<\/a><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiCHxpvvFvW7Br0CVxo5QocMc8Bn6lfXa5y4IffU_ZVHJicud8CYRCERS54yegi0rgFKzBiWHqPAOSnif6HJcVe4CwqvAQYdrvCmVqlWB8nLDwBg3TvWWkTTE9dlxXmjNLvtfAiZLGwTNh5a4TZwi-oOy2tKWHfhJ-nAQkv-r6kK1Jp2vyog43EopqKmoc\/s1600\/Screenshot%25202026-04-03%2520192243%2520%25281%2529.webp?ssl=1\" alt=\"webshell (and its upload path) in action(Source: WatchTowr)\"><figcaption class=\"wp-element-caption\"><em>webshell (and its upload path) in action(Source: WatchTowr)<\/em><\/figcaption><\/figure>\n<\/div>\n<p>In the demonstrated chain, <a href=\"https:\/\/cybersecuritynews.com\/smartertools-smartermail-vulnerability-poc-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">this allowed an ASPX webshell to be placed in the ShareFile webroot<\/a> and for code to be executed remotely on the server.<\/p>\n<p>Progress said it has not received reports of active exploitation so far. However, the vendor classified the issue as critical and published fixes on April 2, 2026.<\/p>\n<p><a href=\"https:\/\/labs.watchtowr.com\/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">WatchTower\u2019s timeline shows the bugs were privately disclosed<\/a> in February, replicated by Progress in mid-February, and fixed in ShareFile Storage Zones Controller 5.12.4 on March 10 before public disclosure in April.<\/p>\n<p>For defenders, the priority is clear: identify any exposed ShareFile Storage Zones Controller 5.x systems, patch immediately, and review them for suspicious configuration changes or unexpected files in web-facing directories.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/progress-sharefile-vulnerability\/\">New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/progress-sharefile-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In A dangerous attack chain in Progress ShareFile that can allow attackers to take over exposed on-premises servers without first logging in. The issues affect customer-managed ShareFile Storage Zones Controller 5.x deployments, and Progress says customers should upgrade to version 5.12.4 or move to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11876","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11876"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11876"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11876\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11876"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11876"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11876"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}