Progress Software disclosed a zero-day path traversal vulnerability in ShareFile Storage Zones Controller tracked as CVE-2026-15724, after previously advising customers to shut down affected servers. The flaw affects all 5.x releases through 5.12.4 and 6.0.0 through 6.0.1, and allows an authenticated administrator to read arbitrary files, write attacker-controlled data to arbitrary directories, and determine whether files exist on the server. The issue carries a CVSS v3.1 vector of AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N and is associated with CWE-22, CWE-20, and CWE-73.
Progress said it learned of a potential threat from a trusted source, identified the previously unknown bug during its investigation, and prepared fixes before public disclosure. The company released patched versions 5.12.5 and 6.0.2, stating that updated servers can be brought back online, while the Canadian Centre for Cyber Security urged organizations to review Progress guidance and apply the necessary updates. Progress also said it has found no evidence so far of customer compromise, unauthorized access to ShareFile accounts or data, or active exploitation affecting customers.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
When disclosing the issue, Progress stated it had not found evidence of customer compromise, unauthorized access to ShareFile accounts or data, or any active threats. The source ties this statement to the disclosure but does not explicitly anchor it to a separate event date beyond the advisory publication.
On 2026-07-21, Progress published security advisories for ShareFile Storage Zones Controller covering the path traversal flaw later tracked as CVE-2026-15724. The company released fixed versions 5.12.5 and 6.0.2 and said patched servers could be brought back online.
Progress disclosed that it had issued emergency guidance to shut down ShareFile Storage Zone Controller servers because of the zero-day vulnerability. The source does not provide a specific date for when the shutdown guidance was first issued.
Progress said it received information about a potential threat from a trusted source, investigated, identified a previously unknown ShareFile Storage Zone Controller vulnerability, and prepared a fix before public disclosure. No specific event date was provided in the source content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecyber.gc.ca
Open sourcecvefeed.io
Open sourcexakep.ru
Open sourcesupport.sharefile.com
Open sourceprogress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.