Advisory ShareFile cloud Storage Zone Controller Progress Software supply-chain
Администраторам Progress рекомендовали срочно отключить серверы ShareFile
CVE Tools coverage
Progress Software has issued an urgent warning to administrators of its ShareFile service, urging them to manually disable Windows servers running the Storage Zone Controller. The company reported a 'real external threat' targeting these controllers and advised clients using this component to cut off access immediately. Although there is no evidence yet of unauthorized access to accounts or data, the threat is considered serious enough that cloud-side blocks were insufficient. In 2023, a similar vulnerability (CVE-2023-24489) was actively exploited, leading CISA to add it to its catalog of known exploited vulnerabilities.