CVE-2026-2701 is a remote code execution vulnerability in Progress ShareFile Storage Zones Controller 5.x for customer-managed deployments. The flaw allows an authenticated or otherwise high-privileged user to upload a malicious file to the server and execute it. Public technical reporting indicates the issue is reachable through file upload and archive extraction functionality, where a crafted archive can be uploaded and extracted into a server-controlled path, including a web-accessible directory, enabling deployment of server-executable content such as an ASPX webshell. In practical attack chains, this vulnerability has been paired with CVE-2026-2699 to first obtain unauthorized access to restricted configuration functionality and then abuse upload behavior to achieve code execution without valid credentials. Affected versions are ShareFile Storage Zones Controller 5.x prior to 5.12.4; ShareFile Storage Zones Controller 6.x is reported as unaffected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical ShareFile Storage Zone Controller vulnerability that, when chained with CVE-2026-2699, could allow unauthenticated attackers to make configuration changes, upload malicious files, and achieve remote code execution.
A vulnerability reportedly theorized to be part of a chained attack against unpatched on-premises Progress ShareFile Storage Zone Controllers, potentially enabling pre-authentication remote code execution when combined with CVE-2026-2699.
A remote code execution vulnerability in Progress ShareFile Storage Zone Controller that, when chained with CVE-2026-2699, allowed unauthenticated attackers to upload malicious ASPX webshells and gain full remote code execution.
A critical vulnerability in Progress ShareFile Storage Zone Controller that, when chained with CVE-2026-2699, allows unauthenticated remote code execution on exposed SZC servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.