← All news

vulnerability

Progress confirms ShareFile Storage Zone zero-day, patches out

2026-07-15

Progress Software has confirmed what a lot of ShareFile customers were already whispering about: last week's abrupt shutdown of Storage Zone Controllers wasn't a cautious over-reaction. It was a live, unpatched zero-day. Fixes are now out, and customers are being told to patch before bringing anything back online.

What the bug actually does

The flaw is a high-severity path traversal issue affecting every 5.x and 6.x version of the Storage Zone Controller. In Progress's own description, an authenticated administrative user could read arbitrary files the service account has rights to, drop attacker-controlled content into arbitrary directories, and generally map out the server filesystem. A CVE has been reserved, but the technical details are being held for two weeks, presumably to give customers a fighting chance to update before the write-ups start circulating.

The fixes are in versions 5.12.5 and 6.0.2.

Why Storage Zones matter

Storage Zone Controllers are the customer-run Windows servers that sit at the heart of ShareFile's hybrid model. They let organisations keep files on their own infrastructure while still using ShareFile's cloud service for authentication, permissions, and collaboration. Convenient for compliance teams who want data to stay on-prem. Also convenient for anyone trying to extort a company, because those boxes are where the actual data lives.

That's the piece worth pausing on. A path traversal bug is bad on any server. On a system whose entire purpose is to hold sensitive files for a business, it's the sort of finding that justifies pulling the whole service down until it's fixed.

What Progress is saying

The company says it acted on a tip from a credible source and, as of writing, has seen no evidence that customer accounts or data have been accessed. It hasn't said whether the bug was discovered internally or reported by an outside researcher. The prior tell was the emergency shutdown itself, which caused enough disruption last week that customers were already asking pointed questions on support forums.

The requirement for an authenticated admin account softens the blow slightly. It's not a bug an anonymous attacker can hit from the internet. But administrative credentials are exactly the kind of thing that gets phished, reused, or lifted from a compromised endpoint. Combine stolen admin access with a bug that lets you read or write anywhere the service can reach, and you've handed an intruder a very tidy path from initial access to whole-filesystem control.

What to do

  • If you run ShareFile Storage Zone Controllers, update to 5.12.5 or 6.0.2 before bringing servers back online.
  • Review admin account activity on those boxes for anything odd in the weeks before the shutdown.
  • Assume the technical details will be public in roughly two weeks. Anything unpatched by then is fair game.

The window Progress has bought its customers is generous by industry standards. Two weeks is more than enough time to get the update rolled out. It's also more than enough time for a determined researcher, or someone less friendly, to work out where to look once the CVE lands.

Progress confirms ShareFile Storage Zone zero-day, patches out | RiskSense