Two critical vulnerabilities, discovered in the secure file transfer platform Progress ShareFile, are once again highlighting the risks that businesses face from chain attacks. When combined, the weaknesses allow sensitive files to be exported without requiring authentication, creating a particularly dangerous scenario for organizations that rely on the platform to manage and share data.

ShareFile is widely used by mid-sized and large businesses for collaboration and document sharing, making it a high-value target for cybercriminals. Similar platforms have been the focus of massive ransomware, with notable examples being the incidents involving Accellion FTA and MOVEit Transfer. Groups such as Clophave exploited technical weaknesses to steal data on a massive scale.
See also: PXA Stealer malware campaign from Vietnam exploits LinkedIn
The technical nature of the vulnerabilities and the role of the Storage Zones Controller
The vulnerabilities were discovered by security firm watchTowr and concern the Storage Zones Controller (SZC) component, a critical ShareFile subsystem that allows businesses to maintain control of their data whether on-premises or in cloud environments.
The first vulnerability, CVE-2026-2699, involves authentication bypass through mishandled HTTP redirects. This could allow an attacker to gain access to the system's administrative interface without credentials. The second, CVE-2026-2701, allows remote code execution, essentially giving full control over the server.
The combination of the two vulnerabilities creates a complete attack chain: from unauthorized access to malware installation. Attackers can modify critical settings, extract security secrets, and install webshells, gaining a permanent presence on the system.

How the attack unfolds in practice
According to watchTowr’s analysis, the attack begins by exploiting the authentication bypass, which opens the door to system administration. From there, attackers can change parameters such as storage paths and so-called platform “secrets.”
See also: Cisco SSM On-Prem: Critical vulnerability threatens enterprise networks
Although full exploitation requires technical steps such as generating valid HMAC signatures and decrypting internal data, these become feasible after the initial breach. The result is the ability to install malicious files into the application core, allowing persistent access and potential mass data leakage.
Extent of exposure and potential risks
The evidence suggests that the attack surface is significant. The ShadowServer Foundation lists hundreds of exposed systems, while estimates suggest tens of thousands of Storage Zones Controller are accessible over the internet.
Although no active attacks have been recorded to date that exploit the full chain, the disclosure of technical details dramatically increases the likelihood that they will be exploited by cybercriminal groups. Historically, such disclosures act as a catalyst for targeted attacks within days.
See also: Claude Code discovered zero-day in Vim and GNU Emacs

Corrections and what businesses should do
Progress Software addressed the vulnerabilities with version 5.12.4, which was released on March 10. This update is considered critical and should be installed immediately by all organizations using affected versions.
The incident highlights once again the importance of quickly updates security, as well as constantly monitoring systems for suspicious activity. In an environment where attacks are becoming increasingly sophisticated, even a small delay can prove disastrous.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
