Progress
Progress Sharefile Storage Zones Controller: vulnerabilidades y CVE
Progress Sharefile Storage Zones Controller tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses6
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16139 | Alta (7.2) | 0.94% | — | 17 ago 2026 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to… |
| CVE-2026-16138 | Alta (8) | 0.83% | — | 17 ago 2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage… |
| CVE-2026-16137 | Alta (7.2) | 0.74% | — | 17 ago 2026 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content… |
| CVE-2026-15724 | Alta (8.7) | 0.52% | — | 21 jul 2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem,… |
| CVE-2026-2701 | Alta (8.8) | 3.4% | — | 2 abr 2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. |
| CVE-2026-2699 | Crítica (9.8) | 3.2% | — | 2 abr 2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.