Progress SoftwareCVE-2026-16137
Progress Software ShareFile Storage Zones Controller: path traversal
High7.2CVE-2026-16137 · Published Aug 17, 2026 · updated Sep 2, 2026
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ShareFile Storage Zones Controller Product | <= 5.12.5 | No fix yet |
Details and references
More Progress Software advisories
All Progress Software| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Progress Software ShareFile Storage Zones Controller: unsafe deserialization | High8.0 | No fix yet |
| Aug 17 | Progress Software ShareFile Storage Zones Controller: remote code execution | High7.2 | No fix yet |
| Aug 12 | Progress Software WhatsUp Gold: remote code execution | High8.8 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: cross-site scripting | High8.0 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: improper authorization | Medium4.3 | 26.0.2 |
| Aug 12 | Progress Software WhatsUp Gold: path traversal | Medium6.8 | 26.0.2 |