Progress Sharefile Storage Zones Controller — known CVE vulnerabilities
Every CVE whose affected-product data names Progress Sharefile Storage Zones Controller, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2026-2699 — CVSS 9.8 (critical): Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This…
CVE-2026-2701 — CVSS 9.1 (critical): Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-15724 — CVSS 8.7 (high): In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path…
CVE-2026-16138 — CVSS 8.0 (high): In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a…
CVE-2026-16137 — CVSS 7.2 (high): In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using…
CVE-2026-16139 — CVSS 7.2 (high): In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper…