« Volver al listado

Progress

Progress Sharefile Storage Zones Controller: vulnerabilidades y CVE

Progress Sharefile Storage Zones Controller tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-16139Alta (7.2)0.94%—17 ago 2026
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to…
CVE-2026-16138Alta (8)0.83%—17 ago 2026
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage…
CVE-2026-16137Alta (7.2)0.74%—17 ago 2026
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content…
CVE-2026-15724Alta (8.7)0.52%—21 jul 2026
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem,…
CVE-2026-2701Alta (8.8)3.4%—2 abr 2026
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-2699Crítica (9.8)3.2%—2 abr 2026
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1059 Command and Scripting Interpreter2
  3. T1005 Data from Local System1
  4. T1190 Exploit Public-Facing Application1
  5. T1505.003 Web Shell1
  6. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Progress