← Vulnerability feed

Vulnerability record · CVE-2026-2701 · published 2 April 2026

CVE-2026-2701: Progress ShareFile Storage Zones Controller authenticated file upload RCE

Progress · Sharefile Storage Zones Controller

An authenticated user can upload a malicious file to the Progress ShareFile Storage Zones Controller and execute it on the server, resulting in remote code execution. The flaw combines unrestricted file upload with code and OS command injection, so a low-privileged account is enough to run code on the host. This matters because it turns ordinary authenticated access into full server compromise.

8.8 CVSS 3.1 High EPSS 3.4% · top 11.5% CWE-78 · OS command injectionCWE-94 · Code injection
8.8CVSS 3.1 base score
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and high EPSS (99th percentile) make this a serious authenticated RCE, though it is not in KEV and requires a valid account.

What it is

An authenticated user can upload a malicious file to the Progress ShareFile Storage Zones Controller and execute it on the server, resulting in remote code execution. The flaw combines unrestricted file upload with code and OS command injection, so a low-privileged account is enough to run code on the host. This matters because it turns ordinary authenticated access into full server compromise.

Impact

An attacker with a valid low-privileged account gains remote code execution on the Storage Zones Controller, giving high impact to confidentiality, integrity and availability of the host and any data it handles.

Attack surface

Reached over the network via the application's file upload functionality; the CVSS vector shows PR:L and UI:N, so a valid authenticated account is required but no user interaction beyond the upload is needed.

Exploitation

Not listed in CISA KEV and no public exploit references are given, but EPSS is 0.54539 (99th percentile), indicating a high predicted likelihood of exploitation activity.

What to do

  • Apply the vendor security update for ShareFile Storage Zones Controller per the Progress advisory.
  • Restrict upload permissions and review which accounts can submit files to the controller.
  • Enforce strict file type and content validation on uploads, and store uploaded files outside executable paths.
  • Run the controller with least privilege and isolate it from other systems to limit post-exploitation reach.
  • Monitor the vendor advisory for updated guidance and interim workarounds.

Detection

  • Alert on file uploads that land in web-accessible or executable directories on the controller.
  • Monitor for unexpected child processes spawned by the controller's web or application service.
  • Review authentication logs for low-privileged accounts performing uploads followed by execution activity.
  • Baseline and alert on new or modified executable files in upload and web root paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-2701 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-2699Progress ShareFile Storage Zones Controller improper access controlCustomer Managed ShareFile Storage Zones Controller (SZC) exposes restricted configuration pages to unauthenticated attackers due to improper access …EPSS 3.2%analysed8.7CVE-2026-15724Progress sharefile storage zones controller improper input validation vulnerabilityIn Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal …EPSS 0.52%8.0CVE-2026-16138Progress sharefile storage zones controller deserialization of untrusted data vulnerabilityIn Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with wr…EPSS 0.83%7.2CVE-2026-16137Progress sharefile storage zones controller path traversal vulnerabilityIn Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable uplo…EPSS 0.74%7.2CVE-2026-16139Progress sharefile storage zones controller improper input validation vulnerabilityIn Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation i…EPSS 0.94%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed

Source: NIST National Vulnerability Database (record CVE-2026-2701), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.