Advisory ShareFile cloud Storage Zone Controller Progress Software supply-chain
Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers
CVE Tools coverage
Progress Software has issued an urgent warning about a 'credible external security threat' affecting its ShareFile Storage Zone Controllers (SZC), prompting the company to disable access to affected accounts and urge customers to manually shut down their on-premises SZC servers. The move follows reports that attackers might be exploiting two vulnerabilities—CVE-2026-2699 and CVE-2026-2701—to gain remote code execution on unpatched systems. While no unauthorized access has been confirmed, Progress is collaborating with cybersecurity experts to investigate the incident and restore services.