Zero-day flaw caused ShareFile Storage Zones outage
Progress confirmed a zero-day vulnerability caused a ShareFile Storage Zones Controller outage and said access was restored after customers applied company patches.
Progress Software confirmed a zero-day vulnerability caused a disruption to its ShareFile Storage Zones Controller service and that access was restored after customers installed patches the company provided. Progress instructed affected customers to shut down Storage Zones Controller servers and to bring systems back online only after applying the updates.
Progress disabled access for all customers using Storage Zones Controllers after detecting a credible external security threat. By July 14 the company reported service had been restored for affected customers. The defect affected Storage Zones Controller versions 5.x and 6.x; Progress developed and distributed patched versions and said controllers will resume normal operation once those patches are installed.
In private communications to customers, Progress described the flaw as a path traversal vulnerability exploitable by an authenticated administrative user. Progress outlined that an attacker holding admin credentials could read files accessible to the application’s service account, write attacker-controlled content to arbitrary directories, or enumerate the server file system layout. The company stated it had no evidence of unauthorized access to ShareFile customer accounts or data and that it had not identified any active threat.
Security professionals who reviewed Progress’s statements called the broad shutdown and the request that customers disconnect servers from the internet unusual given the vendor’s description of the flaw as requiring administrative access. Benjamin Harris, founder and CEO of WatchTowr, questioned whether additional details exist beyond the published description and asked: “Vulnerabilities that already assume an attacker has administrative access do not typically trigger such an aggressive response. So what’s the missing piece? Is there more to the attack than has been disclosed? Has Progress observed attacker activity that warrants a more aggressive response?” He advised defenders to update Storage Zones Controllers immediately and to treat exposed systems as potentially compromised.
Progress told customers to power down Storage Zones Controller servers, install the supplied patches, and then reconnect to the internet. Customers received vulnerability details and remediation instructions via direct communications.
ShareFile Storage Zones Controller is used by organizations that host Storage Zones on their own infrastructure to keep files behind their firewalls while managing them through ShareFile. Security teams are advised to confirm they are running the patched controller versions, verify administrative credentials and service accounts have not been abused, and review logs and network traffic for signs of suspicious activity. Progress reiterated that it had not found signs of unauthorized access and that installing the released patches is required to restore service.








