2026-07-13HIGHexploitedProgress told every on-prem ShareFile Storage Zone Controller customer to power off, then named a path-traversal flaw and shipped fixed builds
Progress ShareFile Storage Zone Controller emergency shutdown
incident · incident:progress-sharefile-storage-zone-controller-shutdown-2026-07
Progress Software ordered all on-premises ShareFile Storage Zone Controller customers to manually shut down their Windows servers on 2026-07-10 over an undisclosed 'credible external security threat'; as of 2026-07-13 no CVE, root cause, patch or restart timeline had been published and the vendor status page still showed the service non-operational. A chainable pre-auth RCE in the same component (CVE-2026-2699/CVE-2026-2701, watchTowr, patched in SZC 5.12.4) is the plausible but unconfirmed working hypothesis.
Coverage
1
first 2026-07-13 → last 2026-09-29
Latest activity
2026-07-14
Progress told every on-prem ShareFile Storage Zone Controller customer to power off, then named a…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe, us
Sources cited
8
7 hosts
Action items (2)
Do-now tasks recorded on the entries about Progress ShareFile Storage Zone Controller emergency shutdown, newest first. Check the date before acting on an older one.
- Apply ShareFile Storage Zone Controller 5.12.5 or 6.0.2 to every on-prem SZC and follow Progress's account-owner recovery instructions before bringing the component back online. This is the fix for the path-traversal flaw behind the 2026-07-10 emergency shutdown, on a component that honeypots had already seen targeted by exploitation attempts against CVE-2026-2699.2026-07-13CVE-2026-2699 +1
- On any on-prem SZC host, run a bounded compromise check for the known chain: unexpected .aspx files under the StorageCenter webroot subdirectories (documentum/cifs/sp) and the IIS worker process w3wp.exe spawning cmd.exe or powershell.exe.2026-07-13CVE-2026-2699 +1
Defender insights
What each entry about Progress ShareFile Storage Zone Controller emergency shutdown tells a defender to do, newest first.
Latest update · triage
Story timeline
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-13/progress-sharefile-storage-zone-controller-shutdown · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-13/progress-sharefile-storage-zone-controller-shutdown · ATT&CK page ↗
Entries about Progress ShareFile Storage Zone Controller emergency shutdown (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Cl0p×1
- Progress ShareFile Storage Zone Controller×1
- Progress ShareFile Storage Zone Controller, chained storage-repointing RCE, exploited alongside CVE-2026-2699; NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)×1
- Progress ShareFile Storage Zone Controller, pre-auth authentication bypass, exploited in the wild from 2026-07-10 (Shadowserver); NEVER CISA KEV-listed (verified against catalogVersion 2026.08.07)×1
Where this entity is cited
Source distribution
- bleepingcomputer.com2 (25%)
- bankinfosecurity.com1 (12%)
- heise.de1 (12%)
- labs.watchtowr.com1 (12%)
- securityweek.com1 (12%)
- status.sharefile.com1 (12%)
- theregister.com1 (12%)
All cited sources (8)
- bankinfosecurity.comBankInfoSecurity (ISMG)https://www.bankinfosecurity.com/progress-urges-sharefile-shutdown-over-credible-threat-a-32210
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/
- heise.deheise onlinehttps://www.heise.de/en/news/Progress-warns-admins-Deactivate-ShareFile-11362439.html
- labs.watchtowr.comwatchTowr Labshttps://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/
- securityweek.comSecurityWeekhttps://www.securityweek.com/progress-prompts-sharefile-storage-zone-controller-shutdown-amid-security-concerns/
- status.sharefile.comProgress ShareFile (vendor status page)https://status.sharefile.com/incidents/c59n5343lbkq
- theregister.comThe Registerhttps://www.theregister.com/security/2026/07/13/progress-orders-emergency-sharefile-server-shutdown-over-mystery-security-threat/5270281