CVE-2026-2699 is a critical authentication bypass vulnerability affecting customer-managed Progress ShareFile Storage Zones Controller (SZC) 5.x deployments prior to version 5.12.4. The flaw is associated with an Execution After Redirect condition in the Admin.aspx configuration page under the ConfigService component. The application issues an HTTP redirect to the login page for unauthenticated requests, but page execution continues, allowing an unauthenticated remote attacker to access restricted administrative configuration functionality. Through this access, an attacker can reach configuration pages intended to require authentication and modify sensitive zone settings, including storage-related and passphrase-related values. On its own, the vulnerability enables unauthorized administrative access and configuration tampering; in documented attack chains, it can also facilitate subsequent exploitation of CVE-2026-2701 to achieve remote code execution on the underlying server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 2 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical ShareFile Storage Zone Controller vulnerability that, when chained with CVE-2026-2701, could allow unauthenticated attackers to make configuration changes, upload malicious files, and achieve remote code execution.
A vulnerability reportedly theorized to be part of a chained attack against unpatched on-premises Progress ShareFile Storage Zone Controllers, potentially enabling pre-authentication remote code execution when combined with CVE-2026-2701.
An authentication bypass vulnerability in Progress ShareFile Storage Zone Controller that could be chained with CVE-2026-2701 to allow unauthenticated attackers to access restricted configuration pages and ultimately achieve remote code execution.
A critical vulnerability in Progress ShareFile Storage Zone Controller that, when chained with CVE-2026-2701, allows unauthenticated remote code execution on exposed SZC servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.