ctipilot.ch

Progress ShareFile Storage Zone Controller — pre-auth authentication bypass, exploited in the wild from 2026-07-10 (Shadowserver); NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)

cve · CVE-2026-2699 single-source

Coverage timeline
3
first 2026-07-13 → last 2026-08-09
Peak priority
high
2 high · 1 notable
Sources cited
7
7 hosts
Sections touched
2
active-threats, updates
Co-occurring entities
3
see Related entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Progress ShareFile Storage Zone Controller

ATT&CK techniques

2 techniques observed across 3 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-09/sharefile-cve-2026-2699-2701-never-kev-listed · 2026-07-14/progress-sharefile-szc-active-exploitation-confirmed · 2026-07-13/progress-sharefile-storage-zone-controller-shutdown · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-13/progress-sharefile-storage-zone-controller-shutdown · ATT&CK page ↗

Story timeline

  1. 2026-08-09Correction — the two Progress ShareFile Storage Zone Controller flaws in this pipeline's W29 round-up were never added to the CISA KEV catalogue, so its 'every one KEV-listed' claim was wrong when written
    updatesEight of the ten CVEs in that entry are KEV-listed; CVE-2026-2699 and CVE-2026-2701 never were
  2. 2026-07-14Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000
    updatesHoneypots record in-the-wild exploitation of the ShareFile Storage Zone Controller auth bypass the same day Progress ordered shutdowns
  3. 2026-07-13Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed
    active-threatsProgress tells all on-prem ShareFile Storage Zone Controller customers to power off their servers over an undisclosed 'credible external security threat'

Where this entity is cited

  • updates2
  • active-threats1

Source distribution

  • bankinfosecurity.com1 (14%)
  • bleepingcomputer.com1 (14%)
  • heise.de1 (14%)
  • labs.watchtowr.com1 (14%)
  • securityweek.com1 (14%)
  • status.sharefile.com1 (14%)
  • theregister.com1 (14%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Progress ShareFile Storage Zone Controller — pre-auth authentication bypass, exploited in the wild from 2026-07-10 (Shadowserver); NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07) (3)

2026-08-09 · view entry permalink →

NOTABLECVE-2026-2699 +1exploitedupdateNATOA2

Correction — the two Progress ShareFile Storage Zone Controller flaws in this pipeline's W29 round-up were never added to the CISA KEV catalogue, so its 'every one KEV-listed' claim was wrong when written

UPDATE · originally covered Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation (2026-07-19)

the delta is a single clause in that entry's summary, and it is one a reader could have acted on.

The entry described four classes of internet-facing enterprise software crossing into confirmed in-the-wild exploitation during ISO week 29, "every one KEV-listed". Eight of the ten identifiers involved bear that out. The SonicWall SMA1000 pair was added on 2026-07-14, Oracle E-Business Suite Payments on 2026-07-15, the AD FS and SharePoint elevation-of-privilege flaws on 2026-07-14, the wider SharePoint remote-code-execution flaw on 2026-07-16, and the two further SharePoint identifiers the entry quoted from CISA's own alert on 2026-04-14 and 2026-07-01 — all before the entry was published. The two Progress ShareFile Storage Zone Controller identifiers, CVE-2026-2699 and CVE-2026-2701, are not in the catalogue and never have been. Because CISA does not remove entries once added, their absence today is not a later withdrawal; the claim did not hold on 2026-07-19 either.

The exploitation claim underneath it is unaffected, and the distinction is the point. The original entry's own sourcing for ShareFile was Shadowserver honeypot telemetry — "first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday", the same day Progress ordered every on-premises Storage Zone Controller powered off (BankInfoSecurity, 2026-07-13). That evidence stood on its own and still does. What the round-up added, and should not have, was a second and independent-looking confirmation from a catalogue that never carried these identifiers. This pipeline's per-CVE coverage made no KEV claim about either identifier at any point — the error entered only in the weekly synthesis, where ten identifiers from four stories were summarised in one clause.

Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.

BankInfoSecurity 2026-07-13
vulnerability09 Aug 14:18Zsingle-sourceOpen finding ↗

2026-07-14 · view entry permalink →

HIGHCVE-2026-2699exploitedupdateNATOB1

Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000

UPDATE · originally covered Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed (2026-07-13)

Two developments harden the picture around Progress's emergency ShareFile Storage Zone Controller (SZC) shutdown order. First, the shutdown was not precautionary in the abstract: the alert "arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit" the pre-auth authentication-bypass flaw CVE-2026-2699, with Shadowserver Foundation honeypots first recording those attempts on Friday 2026-07-10 (BankInfoSecurity, 2026-07-13). This moves the flaw's status from PoC-public to actively exploited. Second, defenders responded at scale — the number of internet-exposed Storage Zone Controllers fell from watchTowr's April count of about 30,000 to roughly 1,000 by 2026-07-13, evidence of widespread emergency power-downs (BankInfoSecurity, 2026-07-13). Progress restored ShareFile cloud-service access for SZC customers but continues to require the on-prem controllers themselves stay powered off pending its investigation, and still reports no evidence of unauthorized access to customer data (The Register, 2026-07-13; Progress ShareFile status, 2026-07-13).

Recorded Future analyst Allan Liska publicly assessed that the pattern "smells like CL0P ransomware group activity," pointing to Clop's long record of mass-exploiting secure file-transfer software (Accellion FTA, GoAnywhere, MOVEit, Cleo Harmony, and Oracle E-Business Suite) (BankInfoSecurity, 2026-07-13). This is a named researcher's hypothesis, not an attribution: Progress has identified no actor and disclosed no root cause.

Defender takeaway. The one-day earlier guidance — treat any exposed SZC as untrusted and keep it powered off rather than patched — is now backed by confirmed in-the-wild exploitation, so it should carry more weight, not less, for any organisation that has not yet acted. Exposure concentrates in the US and Germany, keeping this directly relevant to European on-prem file-exchange operators. The recommended state remains a full power-off of on-prem Storage Zone Controllers until Progress publishes scope; the original entry's shutdown and bounded-compromise-check actions still stand unchanged.

The alert arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit a critical authentication bypass vulnerability the vendor patched earlier this year in its ShareFile Storage Zone Controller software.

Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.

This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and 'shut them all down.'

BankInfoSecurity (ISMG) 2026-07-13
incident14 Jul 12:50Zmulti-sourceOpen finding ↗

2026-07-13 · view entry permalink →

Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed

Progress Software has told every customer running an on-premises ShareFile Storage Zone Controller (SZC) — the self-hosted IIS component that lets ShareFile's SaaS front end store files on customer-controlled storage (local filesystem, SMB, SharePoint, S3/Azure) rather than in Progress's cloud — to manually power off the Windows server hosting it, citing "a credible external security threat" first notified to customers on 2026-07-10 (BleepingComputer, 2026-07-10). Three days on, the vendor status page still lists the Storage Zone Controller service as not operational and under investigation (Progress ShareFile status, 2026-07-13), and Progress has disclosed neither a CVE, a root cause, nor a patch or safe-restart timeline; the mitigation on offer is a full shutdown rather than an update, with no fix published as of this run (heise online, 2026-07-13; SecurityWeek, 2026-07-13). heise characterises the shutdown as a precautionary measure during an ongoing investigation. Progress states it has no indication of unauthorized access to any ShareFile account or data so far. Only on-premises SZC deployments are affected; cloud-only ShareFile tenants are not.

This sits on top of a chainable pre-auth RCE that watchTowr Labs disclosed in the same component in April 2026: CVE-2026-2699 (CVSS 9.8) is a CWE-698 execution-after-redirect authentication bypass in /ConfigService/Admin.aspx, where Response.Redirect() is called with the terminate flag set to false, so the admin page body still renders and executes after the browser is told to redirect to login; CVE-2026-2701 (CVSS 9.1) chains from that access, because the storage-location validation only checks writability, letting an attacker repoint the storage repository at the IIS web root and land an ASPX web shell (watchTowr Labs, 2026-04-02). Both were fixed in Storage Zone Controller 5.12.4 (the 6.x .NET-Core branch was unaffected); watchTowr counted roughly 30,000 internet-facing SZC instances at disclosure. Progress has not said whether the current threat relates to this chain or to a separate issue.

Defender takeaway. This is the same on-prem, internet-facing, managed-file-transfer-adjacent architecture class (ShareFile, MOVEit, GoAnywhere, Cleo) that has repeatedly produced mass pre-auth exploitation, and a vendor ordering customers to pull the plug rather than patch is a strong signal to treat any exposed SZC as untrusted until Progress publishes scope. Regardless of whether the July threat proves related to CVE-2026-2699/2701, any instance still on SZC 5.x below 5.12.4 carries a known, PoC-backed pre-auth RCE and should be upgraded or taken offline now. Since Progress has confirmed no mechanism, treat the CWE-698 chain as the working hunt hypothesis.

Triage: an authenticated administrator legitimately hits /ConfigService/Admin.aspx and receives a normal authenticated session; the anomaly for the known chain is a request to that path that returns a 302 whose response body nonetheless carries the full admin-panel HTML (the execution-after-redirect behaviour) rather than the redirect being honoured, followed by configuration changes to Zone/Primary-Zone-Controller/storage-repository fields outside a change window — and, downstream, an .aspx file appearing under a StorageCenter webroot subdirectory that is not part of the vendor's shipped file set.

We have reason to believe there is a credible external security threat targeting Progress Software's ShareFile Storage Zone Controllers.

Currently, we have no indication of unauthorized access to any Progress ShareFile accounts or data.

Progress Software (via BleepingComputer)

ShareFile customers with Storage Zone Controllers are not operational at this time.

Progress ShareFile (vendor status page) 2026-07-13
incident13 Jul 12:45Zmulti-sourceOpen finding ↗